
CVE-2026-91945
FreeRDP
•
severity
published
An RDP client responding to an outstanding redirected-smartcard request can trigger stack- and heap-based out-of-bounds reads in FreeRDP's server-side decoder by returning oversized ATR lengths. The flaw can terminate servers with smartcard redirection enabled; no remote data-disclosure or code-execution path was demonstrated.
FreeRDP is embedded by remote-desktop projects including GNOME Remote Desktop and KDE's KRdp; downstream exposure and whether the required protocol state occurs before or after desktop-user authentication depend on the integration.
The Status decoder accepts cbAtrLen values larger than its 32-byte pbAtr array, while the GetStatusChange path accepts per-reader cbAtr values larger than its 36-byte rgbAtr array. FreeRDP's debug logging and length-trusting embedding callbacks then consume those unchecked lengths. AddressSanitizer reproduced stack and heap out-of-bounds reads using production-shaped decoders on FreeRDP 3.30.0 and the tested pre-fix master revision.
Reachability requires RDPDR smartcard redirection, an outstanding Status or GetStatusChange request, and a client able to return the matching completion; unsolicited completions are rejected. The issue is classified as CWE-20 and CWE-125. FreeRDP 3.28.0 through 3.30.0 are affected, and version 3.31.0 is the first patched release.
References
Explore our other findings
