PT-2026-92071 · Freerdp+1 · Freerdp+1
CVE-2026-91952
·
Published
2026-09-15
·
Updated
2026-09-24
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
FreeRDP versions prior to 3.31.0
Description
An infinite-loop denial of service occurs during the decoding of AVC444 metablocks when the number of region rectangles exceeds the preallocated worker array size. A malicious RDP server can trigger this by sending crafted AVC444 graphics updates, causing the threaded decode path in the
pool decode rect() function to loop indefinitely. This results in high CPU consumption and prevents the client from operating normally.Recommendations
Update to version 3.31.0 or later.
Exploit
Fix
DoS
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freerdp
Ubuntu