Integer Overflow Vulnerability in FreeRDP Audio Input Redirection Channel
CVE-2026-68580
7.7HIGH
What is CVE-2026-68580?
The vulnerability present in FreeRDP versions prior to 3.29.0 involves integer overflow issues within the audio input redirection channel. It specifically affects backends like ALSA, sndio, WinMM, and OpenSL ES due to improper validation of the FramesPerPacket parameter received from RDP servers. Attackers can exploit this flaw by providing a malicious FramesPerPacket value, potentially leading to heap-based buffer overflows on ALSA and resulting in denial of service across all platforms.
Affected Version(s)
FreeRDP 0 < 3.29.0
FreeRDP 3.29.0
