Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-91955

Опубликовано: 15 сент. 2026
Источник: redhat
CVSS3: 7.5

Описание

FreeRDP before 3.31.0 fails to validate client-supplied DesktopWidth and DesktopHeight values during GCC negotiation, allowing remote attackers to crash the server. Attackers can send crafted RDP packets with zero or oversized dimensions to trigger division-by-zero or assertion failures in multifragment update capability calculations, terminating the server process.

A flaw was found in FreeRDP. FreeRDP contains a flaw where it fails to validate client-supplied desktop dimensions during the Graphics Command Channel (GCC) negotiation. A remote attacker can exploit this by sending crafted Remote Desktop Protocol (RDP) packets with zero or oversized dimensions. This can lead to division-by-zero or assertion failures, causing the server process to terminate and resulting in a denial of service.

Меры по смягчению последствий

To reduce exposure, restrict network access to the FreeRDP server to trusted clients only. Configure firewall rules to limit incoming connections to the RDP port (typically 3389) from known and authorized IP addresses or subnets. If the FreeRDP server is not essential, consider disabling the service to prevent exploitation. Any changes to firewall rules or service status may require a service restart to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freerdpAffected
Red Hat Enterprise Linux 6freerdpOut of support scope
Red Hat Enterprise Linux 7freerdpAffected
Red Hat Enterprise Linux 8freerdpAffected
Red Hat Enterprise Linux 9freerdpAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-369
https://bugzilla.redhat.com/show_bug.cgi?id=2533907FreeRDP: FreeRDP: Denial of Service via crafted desktop dimensions

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 дня назад

[GHSA-4464-r7qj-pgrx: FreeRDP: server stores client Core Data DesktopWidth/Height unvalidated in GCC negotiation]

CVSS3: 7.5
nvd
4 дня назад

FreeRDP before 3.31.0 fails to validate client-supplied DesktopWidth and DesktopHeight values during GCC negotiation, allowing remote attackers to crash the server. Attackers can send crafted RDP packets with zero or oversized dimensions to trigger division-by-zero or assertion failures in multifragment update capability calculations, terminating the server process.

CVSS3: 7.5
debian
4 дня назад

FreeRDP before 3.31.0 fails to validate client-supplied DesktopWidth a ...

CVSS3: 7.5
github
4 дня назад

FreeRDP before 3.31.0 fails to validate client-supplied DesktopWidth and DesktopHeight values during GCC negotiation, allowing remote attackers to crash the server. Attackers can send crafted RDP packets with zero or oversized dimensions to trigger division-by-zero or assertion failures in multifragment update capability calculations, terminating the server process.

7.5 High

CVSS3