Количество 5
Количество 5
CVE-2026-91952
[GHSA-m85m-3qxv-63h5: Infinite loop / CPU DoS in pool_decode_rect]
CVE-2026-91952
FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks with more region rectangles than preallocated worker array size. A malicious RDP server can send crafted AVC444 graphics updates causing the threaded decode path to loop indefinitely, consuming CPU and preventing normal client operation.
CVE-2026-91952
FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks with more region rectangles than preallocated worker array size. A malicious RDP server can send crafted AVC444 graphics updates causing the threaded decode path to loop indefinitely, consuming CPU and preventing normal client operation.
CVE-2026-91952
FreeRDP versions before 3.31.0 contain an infinite-loop denial of serv ...
GHSA-2f6r-w7g3-4q27
FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks with more region rectangles than preallocated worker array size. A malicious RDP server can send crafted AVC444 graphics updates causing the threaded decode path to loop indefinitely, consuming CPU and preventing normal client operation.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-91952 [GHSA-m85m-3qxv-63h5: Infinite loop / CPU DoS in pool_decode_rect] | CVSS3: 6.5 | 0% Низкий | 4 дня назад | |
CVE-2026-91952 FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks with more region rectangles than preallocated worker array size. A malicious RDP server can send crafted AVC444 graphics updates causing the threaded decode path to loop indefinitely, consuming CPU and preventing normal client operation. | CVSS3: 6.5 | 0% Низкий | 4 дня назад | |
CVE-2026-91952 FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks with more region rectangles than preallocated worker array size. A malicious RDP server can send crafted AVC444 graphics updates causing the threaded decode path to loop indefinitely, consuming CPU and preventing normal client operation. | CVSS3: 6.5 | 0% Низкий | 4 дня назад | |
CVE-2026-91952 FreeRDP versions before 3.31.0 contain an infinite-loop denial of serv ... | CVSS3: 6.5 | 0% Низкий | 4 дня назад | |
GHSA-2f6r-w7g3-4q27 FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks with more region rectangles than preallocated worker array size. A malicious RDP server can send crafted AVC444 graphics updates causing the threaded decode path to loop indefinitely, consuming CPU and preventing normal client operation. | CVSS3: 6.5 | 0% Низкий | 4 дня назад |
Уязвимостей на страницу