Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-91948

Опубликовано: 15 сент. 2026
Источник: redhat
CVSS3: 7.5

Описание

FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTION_SHOW_PROTOCOL is enabled. Authenticated clients can queue oversized channel messages that cause buffer underflow and corrupt heap memory including live pointers, potentially enabling code execution.

A flaw was found in FreeRDP. An authenticated client can send specially crafted, oversized messages to the server when the CHANNEL_OPTION_SHOW_PROTOCOL feature is active. This can cause a buffer underflow, leading to corruption of memory and potentially allowing an attacker to execute malicious code on the server.

Меры по смягчению последствий

To mitigate this issue, restrict network access to the FreeRDP server to only trusted clients or localhost. This can be achieved by configuring firewall rules to limit inbound connections to the FreeRDP service port. A restart of the FreeRDP server may be required for network configuration changes to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freerdpAffected
Red Hat Enterprise Linux 6freerdpNot affected
Red Hat Enterprise Linux 7freerdpNot affected
Red Hat Enterprise Linux 8freerdpNot affected
Red Hat Enterprise Linux 9freerdpNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-124
https://bugzilla.redhat.com/show_bug.cgi?id=2533904FreeRDP: FreeRDP: Arbitrary code execution via oversized channel messages in SHOW_PROTOCOL

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 дня назад

[GHSA-9jcm-x588-gh26: SHOW_PROTOCOL live-pointer overwrite]

CVSS3: 7.5
nvd
4 дня назад

FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTION_SHOW_PROTOCOL is enabled. Authenticated clients can queue oversized channel messages that cause buffer underflow and corrupt heap memory including live pointers, potentially enabling code execution.

CVSS3: 7.5
debian
4 дня назад

FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerab ...

CVSS3: 7.5
github
4 дня назад

FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTION_SHOW_PROTOCOL is enabled. Authenticated clients can queue oversized channel messages that cause buffer underflow and corrupt heap memory including live pointers, potentially enabling code execution.

7.5 High

CVSS3