
CVE-2026-91948
FreeRDP
•
severity
published
An RDP client with an established RDPDR static channel using SHOW_PROTOCOL can trigger an out-of-bounds write in FreeRDP's channel tracker, overwriting an adjacent live pointer and potentially causing server-side code execution or a controlled crash. The flaw is an integer underflow in versions 3.28.0 through 3.30.0; assertion-enabled builds abort before the overwrite, while affected assertion-disabled builds reach it.
FreeRDP is embedded by remote-desktop projects including GNOME Remote Desktop and KDE's KRdp; downstream exposure and whether the required channel state occurs before or after desktop-user authentication depend on the integration.
After an oversized-message error, the tracker preserves its offset. A subsequent zero-capacity read reports bytes without consuming them, and the tracker incorrectly adds that count. The next poll then underflows its remaining-size calculation and copies attacker-controlled data beyond the 1,608-byte buffer into later fields of the same heap allocation. Network validation showed the final eight payload bytes replacing the live log pointer immediately before FreeRDP dereferenced it.
The vulnerable path requires a server-side static channel using CHANNEL_OPTION_SHOW_PROTOCOL and a build with NDEBUG defined and verbose WinPR assertions disabled. FreeRDP's documented stable release configuration meets those conditions. The issue is classified as CWE-191 and CWE-787. FreeRDP 3.31.0 is the first patched release.
CVE pending.
References
Explore our other findings
