CVE-2026-91964
EUVD-2026-7864015.09.2026, 16:17
FreeRDP versions before 3.31.0 contain a heap-based buffer overflow in nego_send_negotiation_request when processing Server Redirection PDU messages with attacker-controlled LoadBalanceInfo fields. A malicious RDP server can trigger the overflow by sending an arbitrary-length field that gets written to a fixed 512-byte buffer without validation, causing client crashes or potential code execution when chained with memory disclosure.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| freerdp | freerdp | 2.0.0 ≤ 𝑥 < 3.0.0 | CNA |
| freerdp | freerdp | 3.0.0 ≤ 𝑥 < 3.31.0 | CNA |
| freerdp | freerdp | 𝑥 < 3.31.0 | CNA |
Debian Releases