CVE-2026-91945
EUVD-2026-7880215.09.2026, 16:17
FreeRDP versions before 3.31.0 contain an out-of-bounds read vulnerability in smartcard response decoders that fail to validate ATR length fields against fixed inline arrays. Authenticated RDP clients can send oversized ATR lengths in PAKID_CORE_DEVICE_IOCOMPLETION responses to trigger reads past stack or heap objects, causing process termination.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| freerdp | freerdp | 3.28.0 ≤ 𝑥 < 3.31.0 | CNA |
Debian Releases
Common Weakness Enumeration
References