PT-2026-92067 · Freerdp+1 · Freerdp+1

·

CVE-2026-91948

·

Published

2026-09-15

·

Updated

2026-09-16

CVSS v4.0

7.7

High

VectorAV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.31.0
Description An out-of-bounds write issue exists in server-side static virtual channel handling when CHANNEL OPTION SHOW PROTOCOL is enabled. Authenticated clients can queue oversized channel messages, leading to a buffer underflow that corrupts heap memory and live pointers, which may allow for remote code execution.
Recommendations Update to version 3.31.0 or later. Disable the CHANNEL OPTION SHOW PROTOCOL option to mitigate the risk.

Exploit

Fix

Integer Underflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91948
GHSA-9JCM-X588-GH26

Affected Products

Freerdp
Ubuntu