PT-2026-92072 · Freerdp+1 · Freerdp+1

CVE-2026-91953

·

Published

2026-09-15

·

Updated

2026-09-24

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.31.0
Description A heap buffer overflow occurs in the nego send negotiation request() function due to a failure to validate the length of the LB LOAD BALANCE INFO field before writing it to a fixed 512-byte buffer. A malicious RDP server or a man-in-the-middle attacker can send a Server Redirection PDU containing an oversized LB LOAD BALANCE INFO value to overflow the buffer with controlled content. This can lead to heap corruption or a denial of service before the authentication process is completed.
Recommendations Update to version 3.31.0 or later.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91953
GHSA-R9PV-FFPH-6GG6

Affected Products

Freerdp
Ubuntu