PT-2026-92081 · Freerdp+1 · Freerdp+1

·

CVE-2026-91962

·

Published

2026-09-15

·

Updated

2026-09-23

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.31.0
Description An integer overflow exists in the audin Apple backends when processing FramesPerPacket values from MSG SNDIN OPEN messages. An attacker can provide crafted FramesPerPacket values that cause the size computation in the AudioQueueAllocateBuffer() function to wrap. This leads to the allocation of an undersized buffer, which may result in out-of-bounds access. Real-world incidents indicate this issue has been exploited in the wild.
Recommendations Update FreeRDP to version 3.31.0 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91962
GHSA-F5P6-88MH-59VG

Affected Products

Freerdp
Ubuntu