Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-91961

Опубликовано: 15 сент. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

FreeRDP before 3.31.0 contains a denial-of-service vulnerability in the URBDRC control-transfer request path that fails to validate OutputBufferSize before forwarding to the libusb backend. A malicious RDP server can send a control-transfer request with OutputBufferSize set to 65536, triggering a reachable assertion that terminates the client process.

A flaw was found in FreeRDP. A malicious Remote Desktop Protocol (RDP) server can send a Universal Serial Bus (USB) Redirection for Remote Desktop Connection (URBDRC) control-transfer request with an invalid OutputBufferSize. This can trigger an assertion in the client process, leading to a denial of service where the client application terminates unexpectedly.

Меры по смягчению последствий

To mitigate this issue, users should only connect to trusted RDP servers. Additionally, running the FreeRDP client within a sandboxed environment can help limit the potential impact of such vulnerabilities.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freerdpAffected
Red Hat Enterprise Linux 6freerdpOut of support scope
Red Hat Enterprise Linux 7freerdpAffected
Red Hat Enterprise Linux 8freerdpAffected
Red Hat Enterprise Linux 9freerdpAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-617
https://bugzilla.redhat.com/show_bug.cgi?id=2533968FreeRDP: FreeRDP: Denial of Service via URBDRC control-transfer request with invalid OutputBufferSize

EPSS

Процентиль: 28%
0.00346
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
3 дня назад

[GHSA-w9qg-g24r-77f6: URBDRC/libusb control-transfer path aborts on reachable OutputBufferSize assertion]

CVSS3: 6.5
nvd
3 дня назад

FreeRDP before 3.31.0 contains a denial-of-service vulnerability in the URBDRC control-transfer request path that fails to validate OutputBufferSize before forwarding to the libusb backend. A malicious RDP server can send a control-transfer request with OutputBufferSize set to 65536, triggering a reachable assertion that terminates the client process.

CVSS3: 6.5
debian
3 дня назад

FreeRDP before 3.31.0 contains a denial-of-service vulnerability in th ...

CVSS3: 6.5
github
3 дня назад

FreeRDP before 3.31.0 contains a denial-of-service vulnerability in the URBDRC control-transfer request path that fails to validate OutputBufferSize before forwarding to the libusb backend. A malicious RDP server can send a control-transfer request with OutputBufferSize set to 65536, triggering a reachable assertion that terminates the client process.

EPSS

Процентиль: 28%
0.00346
Низкий

6.5 Medium

CVSS3