Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-91945

Опубликовано: 15 сент. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

FreeRDP versions before 3.31.0 contain an out-of-bounds read vulnerability in smartcard response decoders that fail to validate ATR length fields against fixed inline arrays. Authenticated RDP clients can send oversized ATR lengths in PAKID_CORE_DEVICE_IOCOMPLETION responses to trigger reads past stack or heap objects, causing process termination.

A flaw was found in FreeRDP. Authenticated RDP clients can exploit an out-of-bounds read vulnerability in smartcard response decoders. This occurs because the decoders fail to validate the length of Answer to Reset (ATR) fields against fixed inline arrays. By sending oversized ATR lengths, an attacker can trigger reads past memory objects, leading to process termination and a denial of service.

Меры по смягчению последствий

To mitigate this issue, disable smartcard redirection when connecting to RDP servers using FreeRDP. This can typically be achieved by using the --disable-smartcard command-line option for xfreerdp or similar configuration in other FreeRDP-based clients. Disabling smartcard redirection may impact functionality that relies on smartcard authentication or access within the RDP session.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freerdpAffected
Red Hat Enterprise Linux 6freerdpNot affected
Red Hat Enterprise Linux 7freerdpNot affected
Red Hat Enterprise Linux 8freerdpNot affected
Red Hat Enterprise Linux 9freerdpNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2533965FreeRDP: FreeRDP: Denial of Service due to out-of-bounds read in smartcard response processing

EPSS

Процентиль: 46%
0.00567
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
4 дня назад

[GHSA-q65v-4w7q-hx3r: Smartcard response lengths are not bounded to their inline ATR arrays]

CVSS3: 6.5
nvd
4 дня назад

FreeRDP versions before 3.31.0 contain an out-of-bounds read vulnerability in smartcard response decoders that fail to validate ATR length fields against fixed inline arrays. Authenticated RDP clients can send oversized ATR lengths in PAKID_CORE_DEVICE_IOCOMPLETION responses to trigger reads past stack or heap objects, causing process termination.

CVSS3: 6.5
debian
4 дня назад

FreeRDP versions before 3.31.0 contain an out-of-bounds read vulnerabi ...

CVSS3: 6.5
github
4 дня назад

FreeRDP versions before 3.31.0 contain an out-of-bounds read vulnerability in smartcard response decoders that fail to validate ATR length fields against fixed inline arrays. Authenticated RDP clients can send oversized ATR lengths in PAKID_CORE_DEVICE_IOCOMPLETION responses to trigger reads past stack or heap objects, causing process termination.

EPSS

Процентиль: 46%
0.00567
Низкий

6.5 Medium

CVSS3