Bug 2533911 (CVE-2026-91964) - CVE-2026-91964 FreeRDP: FreeRDP: Remote code execution via heap buffer overflow in Server Redirection PDU
Summary: CVE-2026-91964 FreeRDP: FreeRDP: Remote code execution via heap buffer overfl...
Keywords:
Status: NEW
Alias: CVE-2026-91964
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2534097 2534099
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-15 15:48 UTC by OSIDB Bzimport
Modified: 2026-09-15 18:39 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-15 15:48:43 UTC
FreeRDP versions before 3.31.0 contain a heap-based buffer overflow in nego_send_negotiation_request when processing Server Redirection PDU messages with attacker-controlled LoadBalanceInfo fields. A malicious RDP server can trigger the overflow by sending an arbitrary-length field that gets written to a fixed 512-byte buffer without validation, causing client crashes or potential code execution when chained with memory disclosure.


Note You need to log in before you can comment on or make changes to this bug.