Heap-Based Buffer Overflow in FreeRDP Affects Multiple Versions
CVE-2026-91964

8.7HIGH

Key Information:

Vendor

Freerdp

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-91964?

The FreeRDP application exhibits a heap-based buffer overflow vulnerability when handling Server Redirection PDU messages, specifically in the nego_send_negotiation_request function. This flaw arises due to the improper management of attacker-controlled LoadBalanceInfo fields, allowing malicious RDP servers to craft messages that exceed a 512-byte buffer limit. This exploitation could lead to client crashes and may be leveraged for arbitrary code execution, especially when combined with other vulnerabilities that disclose sensitive memory content.

Affected Version(s)

FreeRDP 2.0.0 < 3.0.0

FreeRDP 3.0.0 < 3.31.0

FreeRDP 0 < 3.31.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

iarce-qb
.