PT-2026-92064 · Freerdp+1 · Freerdp+1

·

CVE-2026-91945

·

Published

2026-09-15

·

Updated

2026-09-24

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.31.0
Description An out-of-bounds read occurs in smartcard response decoders due to a failure to validate ATR length fields against fixed inline arrays. Authenticated RDP clients can trigger this by sending oversized ATR lengths in PAKID CORE DEVICE IOCOMPLETION responses, leading to reads past stack or heap objects and resulting in process termination.
Recommendations Update to version 3.31.0 or later.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91945
GHSA-Q65V-4W7Q-HX3R

Affected Products

Freerdp
Ubuntu