Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-91962

Опубликовано: 15 сент. 2026
Источник: redhat
CVSS3: 6.3
EPSS Низкий

Описание

FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values from MSG_SNDIN_OPEN messages. Attackers can supply crafted FramesPerPacket values that cause AudioQueueAllocateBuffer size computation to wrap, resulting in undersized buffer allocation and potential out-of-bounds access.

A flaw was found in FreeRDP. An integer overflow in the audin Apple backends, specifically when processing FramesPerPacket values from MSG_SNDIN_OPEN messages, allows a malicious RDP (Remote Desktop Protocol) server to supply crafted values. This can cause the AudioQueueAllocateBuffer size computation to wrap, leading to an undersized buffer allocation and potential out-of-bounds access. This memory safety issue could result in information disclosure, denial of service, or potentially arbitrary code execution.

Меры по смягчению последствий

To mitigate this issue, ensure that FreeRDP is not configured to use the audin Apple backends. This specific functionality is not typically enabled by default in Red Hat Enterprise Linux environments. If FreeRDP is used to connect to macOS systems and audio input redirection is enabled, consider disabling this feature or restricting connections to trusted remote desktop servers.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freerdpFix deferred
Red Hat Enterprise Linux 6freerdpOut of support scope
Red Hat Enterprise Linux 7freerdpFix deferred
Red Hat Enterprise Linux 8freerdpFix deferred
Red Hat Enterprise Linux 9freerdpFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2533933FreeRDP: FreeRDP: Remote out-of-bounds access via integer overflow in audin Apple backends

EPSS

Процентиль: 16%
0.00244
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.3
ubuntu
3 дня назад

[GHSA-f5p6-88mh-59vg: audin Apple backends perform overflow-prone buffer size arithmetic from server-controlled values]

CVSS3: 6.3
nvd
3 дня назад

FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values from MSG_SNDIN_OPEN messages. Attackers can supply crafted FramesPerPacket values that cause AudioQueueAllocateBuffer size computation to wrap, resulting in undersized buffer allocation and potential out-of-bounds access.

CVSS3: 6.3
debian
3 дня назад

FreeRDP before 3.31.0 contains an integer overflow in the audin Apple ...

CVSS3: 6.3
github
3 дня назад

FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values from MSG_SNDIN_OPEN messages. Attackers can supply crafted FramesPerPacket values that cause AudioQueueAllocateBuffer size computation to wrap, resulting in undersized buffer allocation and potential out-of-bounds access.

EPSS

Процентиль: 16%
0.00244
Низкий

6.3 Medium

CVSS3