FreeRDP

•

severity

7.5

published

An RDP client with an established RDPDR static channel using SHOW_PROTOCOL can trigger an out-of-bounds write in FreeRDP's channel tracker, overwriting an adjacent live pointer and potentially causing server-side code execution or a controlled crash. The flaw is an integer underflow in versions 3.28.0 through 3.30.0; assertion-enabled builds abort before the overwrite, while affected assertion-disabled builds reach it.

FreeRDP is embedded by remote-desktop projects including GNOME Remote Desktop and KDE's KRdp; downstream exposure and whether the required channel state occurs before or after desktop-user authentication depend on the integration.

After an oversized-message error, the tracker preserves its offset. A subsequent zero-capacity read reports bytes without consuming them, and the tracker incorrectly adds that count. The next poll then underflows its remaining-size calculation and copies attacker-controlled data beyond the 1,608-byte buffer into later fields of the same heap allocation. Network validation showed the final eight payload bytes replacing the live log pointer immediately before FreeRDP dereferenced it.

The vulnerable path requires a server-side static channel using CHANNEL_OPTION_SHOW_PROTOCOL and a build with NDEBUG defined and verbose WinPR assertions disabled. FreeRDP's documented stable release configuration meets those conditions. The issue is classified as CWE-191 and CWE-787. FreeRDP 3.31.0 is the first patched release.

CVE pending.

References

CVSS v3.1

7.5

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v3.1

7.5

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v3.1

7.5

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

SJtVaCrOtY  lPo6o1kBiBn1gJ  a1t9  yOoJuEr8  sDoJf#tCwLaGr0eG  c8r&iLtAiOc#a$lAlGy@.F

request briefing

request briefing

SKtYa0rRt7  l1oZoZkFiKnDgX  a#tV  yYoEu@r7  s#o6fNtMw4aGrAe1  cTrDiQtQi#c#aXl0lCyS.&

request briefing

request briefing

SItAaDrHt%  lQoLoKkQi$nEgM  aCtX  y1o&uAr5  s@oGf&tFw8aKr4eZ  cCrBi4t2iDcBaVlJl4yZ.N

request briefing

request briefing

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026