Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-91960

Опубликовано: 15 сент. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allows remote attackers to cause denial of service. A malicious RD Gateway peer can send a WebSocket Ping frame with a crafted 64-bit extended payload length to trigger integer wraparound, resulting in a double free that crashes the FreeRDP client during connection.

A flaw was found in FreeRDP. A remote attacker, specifically a malicious RD Gateway peer, could send a crafted WebSocket Ping frame with an extended payload length. This action triggers an an integer overflow in the Stream_EnsureRemainingCapacity function, leading to an integer wraparound and a double free vulnerability. Successful exploitation results in a denial of service, causing the FreeRDP client to crash during connection.

Меры по смягчению последствий

To mitigate this issue, FreeRDP clients should only connect to trusted and verified Remote Desktop Gateway servers. Connecting to untrusted or unverified servers may expose the client to denial of service attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freerdpAffected
Red Hat Enterprise Linux 6freerdpOut of support scope
Red Hat Enterprise Linux 7freerdpAffected
Red Hat Enterprise Linux 8freerdpAffected
Red Hat Enterprise Linux 9freerdpAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2533957FreeRDP: FreeRDP: Denial of Service via integer overflow and double free in WinPR

EPSS

Процентиль: 38%
0.00442
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
3 дня назад

[GHSA-vccg-35r5-8jrf: Stream_EnsureCapacity still overflows]

CVSS3: 6.5
nvd
3 дня назад

FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allows remote attackers to cause denial of service. A malicious RD Gateway peer can send a WebSocket Ping frame with a crafted 64-bit extended payload length to trigger integer wraparound, resulting in a double free that crashes the FreeRDP client during connection.

CVSS3: 6.5
debian
3 дня назад

FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's ...

CVSS3: 6.5
github
3 дня назад

FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allows remote attackers to cause denial of service. A malicious RD Gateway peer can send a WebSocket Ping frame with a crafted 64-bit extended payload length to trigger integer wraparound, resulting in a double free that crashes the FreeRDP client during connection.

EPSS

Процентиль: 38%
0.00442
Низкий

6.5 Medium

CVSS3