Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-91954

Опубликовано: 15 сент. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

FreeRDP before 3.31.0 contains a null pointer dereference vulnerability in gdi_surface_bits when processing Surface Bits commands with NSCodec codec ID. A malicious RDP server can crash a FreeRDP client by sending a crafted Surface Bits command claiming to use NSCodec, even when the codec is disabled.

A flaw was found in FreeRDP. A malicious Remote Desktop Protocol (RDP) server can trigger a null pointer dereference in the gdi_surface_bits function by sending a specially crafted Surface Bits command that claims to use the NSCodec codec ID. This vulnerability exists even when the NSCodec is disabled in the client. Successful exploitation allows a remote attacker to cause a FreeRDP client to crash, leading to a denial of service.

Меры по смягчению последствий

To mitigate this issue, users should avoid connecting to untrusted or unknown RDP servers with FreeRDP clients. This vulnerability requires a FreeRDP client to connect to a malicious RDP server to be exploited.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freerdpAffected
Red Hat Enterprise Linux 6freerdpOut of support scope
Red Hat Enterprise Linux 7freerdpAffected
Red Hat Enterprise Linux 8freerdpAffected
Red Hat Enterprise Linux 9freerdpAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2533906FreeRDP: FreeRDP: Denial of Service via crafted Surface Bits command

EPSS

Процентиль: 28%
0.00346
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
4 дня назад

[GHSA-ffjr-p229-hpch: NULL pointer dereference in gdi_surface_bits when the client has not enabled NSCodec]

CVSS3: 6.5
nvd
4 дня назад

FreeRDP before 3.31.0 contains a null pointer dereference vulnerability in gdi_surface_bits when processing Surface Bits commands with NSCodec codec ID. A malicious RDP server can crash a FreeRDP client by sending a crafted Surface Bits command claiming to use NSCodec, even when the codec is disabled.

CVSS3: 6.5
debian
4 дня назад

FreeRDP before 3.31.0 contains a null pointer dereference vulnerabilit ...

CVSS3: 6.5
github
4 дня назад

FreeRDP before 3.31.0 contains a null pointer dereference vulnerability in gdi_surface_bits when processing Surface Bits commands with NSCodec codec ID. A malicious RDP server can crash a FreeRDP client by sending a crafted Surface Bits command claiming to use NSCodec, even when the codec is disabled.

EPSS

Процентиль: 28%
0.00346
Низкий

6.5 Medium

CVSS3