PT-2026-92070 · Freerdp+1 · Freerdp+1

·

CVE-2026-91951

·

Published

2026-09-15

·

Updated

2026-09-24

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.31.0
Description An out-of-bounds write occurs in the urbdrc client channel's urb send current frame number result() function. A malicious RDP server can send a crafted 28-byte USB redirection message to trigger a 4-byte write past the allocated 16-byte buffer, resulting in a denial of service when verbose asserts are enabled.
Recommendations Update to version 3.31.0 or later.

Exploit

Fix

DoS

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91951
GHSA-H5W2-Q35J-443H

Affected Products

Freerdp
Ubuntu