Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-91952

Опубликовано: 15 сент. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks with more region rectangles than preallocated worker array size. A malicious RDP server can send crafted AVC444 graphics updates causing the threaded decode path to loop indefinitely, consuming CPU and preventing normal client operation.

A flaw was found in FreeRDP. A malicious Remote Desktop Protocol (RDP) server can send specially crafted AVC444 graphics updates. This can cause the pool_decode_rect function to enter an infinite loop when decoding AVC444 metablocks with an excessive number of region rectangles. The vulnerability leads to a denial of service (DoS) by consuming CPU resources and preventing normal client operation.

Меры по смягчению последствий

To mitigate this issue, users should avoid connecting FreeRDP clients to untrusted or unverified RDP servers. Restricting RDP client connections to known, legitimate servers reduces the risk of encountering a malicious server exploiting this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freerdpAffected
Red Hat Enterprise Linux 6freerdpOut of support scope
Red Hat Enterprise Linux 7freerdpAffected
Red Hat Enterprise Linux 8freerdpAffected
Red Hat Enterprise Linux 9freerdpAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-606
https://bugzilla.redhat.com/show_bug.cgi?id=2533948FreeRDP: FreeRDP: Denial of Service via crafted AVC444 graphics updates

EPSS

Процентиль: 28%
0.00346
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
4 дня назад

[GHSA-m85m-3qxv-63h5: Infinite loop / CPU DoS in pool_decode_rect]

CVSS3: 6.5
nvd
4 дня назад

FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks with more region rectangles than preallocated worker array size. A malicious RDP server can send crafted AVC444 graphics updates causing the threaded decode path to loop indefinitely, consuming CPU and preventing normal client operation.

CVSS3: 6.5
debian
4 дня назад

FreeRDP versions before 3.31.0 contain an infinite-loop denial of serv ...

CVSS3: 6.5
github
4 дня назад

FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks with more region rectangles than preallocated worker array size. A malicious RDP server can send crafted AVC444 graphics updates causing the threaded decode path to loop indefinitely, consuming CPU and preventing normal client operation.

EPSS

Процентиль: 28%
0.00346
Низкий

6.5 Medium

CVSS3