PT-2026-92074 · Freerdp+1 · Freerdp+1

CVE-2026-91955

·

Published

2026-09-15

·

Updated

2026-09-24

CVSS v4.0

8.2

High

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.31.0
Description Remote attackers can cause a server crash by sending crafted RDP packets with zero or oversized values for the DesktopWidth and DesktopHeight variables during GCC negotiation. This lack of validation triggers division-by-zero or assertion failures during multifragment update capability calculations, which terminates the server process.
Recommendations Update to version 3.31.0 or later.

Exploit

Fix

Divide By Zero

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91955
GHSA-4464-R7QJ-PGRX

Affected Products

Freerdp
Ubuntu