PT-2026-92071 · Freerdp+1 · Freerdp+1

CVE-2026-91952

·

Published

2026-09-15

·

Updated

2026-09-24

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.31.0
Description An infinite-loop denial of service occurs during the decoding of AVC444 metablocks when the number of region rectangles exceeds the preallocated worker array size. A malicious RDP server can trigger this by sending crafted AVC444 graphics updates, causing the threaded decode path in the pool decode rect() function to loop indefinitely. This results in high CPU consumption and prevents the client from operating normally.
Recommendations Update to version 3.31.0 or later.

Exploit

Fix

DoS

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91952
GHSA-M85M-3QXV-63H5

Affected Products

Freerdp
Ubuntu