PT-2026-66342 · Freerdp · Freerdp

CVE-2026-63117

·

Published

2026-07-28

·

Updated

2026-09-07

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.28.0
Description An authenticated RDP client can cause the server-side rdpsnd channel process to terminate by advertising DVI ADPCM with nBlockAlign equal to 8 and nChannels equal to 2. This configuration results in the bs calculation within the rdpsnd server select format() function in channels/rdpsnd/server/rdpsnd main.c becoming zero. Consequently, the out frames modulo bs operation triggers a SIGFPE (Signal Floating-Point Exception), which is a signal sent to a process when a mathematical error occurs, such as division by zero.
Recommendations Update to version 3.28.0 or later.

Exploit

Fix

DoS

Divide By Zero

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63117
GHSA-V64M-XXFW-HRV6
OPENSUSE-SU-2026:11385-1

Affected Products

Freerdp