Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-91950

Опубликовано: 15 сент. 2026
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the rdpdr_dump_packet function due to 32-bit unsigned integer wraparound in buffer bounds validation. A malicious RDP server can send a crafted RDPDR packet with computerNameLen set to 0xFFFFFFF0 to bypass bounds checks and trigger memory reads past the packet buffer, causing client crashes or heap disclosure in logs.

A flaw was found in FreeRDP, where an out-of-bounds read vulnerability exists in the rdpdr_dump_packet function. This is due to a 32-bit unsigned integer wraparound during buffer bounds validation. A malicious RDP server can send a specially crafted RDPDR packet, bypassing security checks and causing the client to read memory beyond the intended buffer. This can result in client crashes, leading to a denial of service, or the disclosure of sensitive heap memory information in logs. Exploitation requires the client to have WLOG_TRACE-level logging enabled.

Меры по смягчению последствий

To mitigate this issue, users should avoid connecting to untrusted or potentially malicious RDP servers. Restricting FreeRDP client connections to only known and trusted RDP servers significantly reduces the attack surface. If connecting to untrusted servers is unavoidable, consider using a highly isolated environment for the client.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freerdpAffected
Red Hat Enterprise Linux 6freerdpOut of support scope
Red Hat Enterprise Linux 7freerdpAffected
Red Hat Enterprise Linux 8freerdpAffected
Red Hat Enterprise Linux 9freerdpAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2533954FreeRDP: FreeRDP: Out-of-bounds read leads to denial of service or information disclosure

EPSS

Процентиль: 39%
0.00451
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
4 дня назад

[GHSA-c5gr-hmqp-pwj4: RDPDR out-of-bounds read in rdpdr_dump_packet via UINT32 wraparound in 16 + computerNameLen guard]

CVSS3: 6.5
nvd
4 дня назад

FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the rdpdr_dump_packet function due to 32-bit unsigned integer wraparound in buffer bounds validation. A malicious RDP server can send a crafted RDPDR packet with computerNameLen set to 0xFFFFFFF0 to bypass bounds checks and trigger memory reads past the packet buffer, causing client crashes or heap disclosure in logs.

CVSS3: 6.5
debian
4 дня назад

FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in ...

CVSS3: 6.5
github
4 дня назад

FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the rdpdr_dump_packet function due to 32-bit unsigned integer wraparound in buffer bounds validation. A malicious RDP server can send a crafted RDPDR packet with computerNameLen set to 0xFFFFFFF0 to bypass bounds checks and trigger memory reads past the packet buffer, causing client crashes or heap disclosure in logs.

EPSS

Процентиль: 39%
0.00451
Низкий

7.1 High

CVSS3