Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-91964

Опубликовано: 15 сент. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

FreeRDP versions before 3.31.0 contain a heap-based buffer overflow in nego_send_negotiation_request when processing Server Redirection PDU messages with attacker-controlled LoadBalanceInfo fields. A malicious RDP server can trigger the overflow by sending an arbitrary-length field that gets written to a fixed 512-byte buffer without validation, causing client crashes or potential code execution when chained with memory disclosure.

A flaw was found in FreeRDP. A malicious Remote Desktop Protocol (RDP) server can exploit a heap-based buffer overflow vulnerability in the nego_send_negotiation_request function. By sending a specially crafted Server Redirection PDU message with an attacker-controlled LoadBalanceInfo field, the server can write an arbitrary-length field into a fixed-size buffer without proper validation. This can lead to a denial of service (client crash) or, when chained with a memory disclosure vulnerability, potentially remote code execution on the client system.

Меры по смягчению последствий

Users of FreeRDP clients should avoid connecting to untrusted or unknown RDP servers. This operational control reduces the risk of exploitation, as a malicious server is required to trigger the heap-based buffer overflow.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freerdpAffected
Red Hat Enterprise Linux 6freerdpOut of support scope
Red Hat Enterprise Linux 7freerdpAffected
Red Hat Enterprise Linux 8freerdpAffected
Red Hat Enterprise Linux 9freerdpAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2533911FreeRDP: FreeRDP: Remote code execution via heap buffer overflow in Server Redirection PDU

EPSS

Процентиль: 45%
0.00549
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
3 дня назад

[GHSA-2vf2-grvj-6g8x: Heap buffer overflow in nego_send_negotiation_request]

CVSS3: 8.8
nvd
3 дня назад

FreeRDP versions before 3.31.0 contain a heap-based buffer overflow in nego_send_negotiation_request when processing Server Redirection PDU messages with attacker-controlled LoadBalanceInfo fields. A malicious RDP server can trigger the overflow by sending an arbitrary-length field that gets written to a fixed 512-byte buffer without validation, causing client crashes or potential code execution when chained with memory disclosure.

CVSS3: 8.8
debian
3 дня назад

FreeRDP versions before 3.31.0 contain a heap-based buffer overflow in ...

CVSS3: 8.8
github
3 дня назад

FreeRDP versions before 3.31.0 contain a heap-based buffer overflow in nego_send_negotiation_request when processing Server Redirection PDU messages with attacker-controlled LoadBalanceInfo fields. A malicious RDP server can trigger the overflow by sending an arbitrary-length field that gets written to a fixed 512-byte buffer without validation, causing client crashes or potential code execution when chained with memory disclosure.

EPSS

Процентиль: 45%
0.00549
Низкий

8.8 High

CVSS3