Heap-Based Buffer Overflow in FreeRDP Affects Multiple Versions
CVE-2026-91964
8.7HIGH
What is CVE-2026-91964?
The FreeRDP application exhibits a heap-based buffer overflow vulnerability when handling Server Redirection PDU messages, specifically in the nego_send_negotiation_request function. This flaw arises due to the improper management of attacker-controlled LoadBalanceInfo fields, allowing malicious RDP servers to craft messages that exceed a 512-byte buffer limit. This exploitation could lead to client crashes and may be leveraged for arbitrary code execution, especially when combined with other vulnerabilities that disclose sensitive memory content.
Affected Version(s)
FreeRDP 2.0.0 < 3.0.0
FreeRDP 3.0.0 < 3.31.0
FreeRDP 0 < 3.31.0
