Description
FreeRDP versions before 3.31.0 contain an out-of-bounds read vulnerability in smartcard response decoders that fail to validate ATR length fields against fixed inline arrays. Authenticated RDP clients can send oversized ATR lengths in PAKID_CORE_DEVICE_IOCOMPLETION responses to trigger reads past stack or heap objects, causing process termination.
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Out‑of‑bounds read that can crash an RDP client
Action: Patch
AI Analysis

Impact

FreeRDP versions before 3.31.0 contain an out‑of‑bounds read in the smartcard ATR decoder that does not validate the length field of the ATR against the size of a fixed inline array. An attacker who can send an RDP packet that includes a PAKID_CORE_DEVICE_IOCOMPLETION response with an oversized ATR length can cause the decoder to read past the bounds of the array. The read occurs on the stack or heap and results in process termination, which can be used to crash the RDP client or impair service availability. The weakness is classified as CWE‑125, an out‑of‑bounds read.

Affected Systems

All FreeRDP clients whose installed version is earlier than 3.31.0 are affected. This includes any system using the up‑to‑date open‑source RDP client distributions that have not applied the 3.31.0 release or later.

Risk and Exploitability

The CVSS base score of 7.1 indicates a high severity. The EPSS score is < 1%, indicating a very low but nonzero exploitation probability; however, because the vulnerability requires an authenticated client context, an attacker would need network access to the target RDP session or the ability to inject crafted packets. The vulnerability is not listed in CISA’s KEV catalog, and no public exploit is known, but the nature of the fault allows a crash, which can be leveraged for denial of service or to pivot to further attacks if the application is compromised. The likely attack vector is a malicious RDP client that can send custom PAKID_CORE_DEVICE_IOCOMPLETION packets.

Generated by OpenCVE AI on September 20, 2026 at 16:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade FreeRDP to version 3.31.0 or later, which contains the fix for the smartcard ATR length validation.
  • Disable smartcard authentication or usage on the client if it is not required, thereby eliminating the vulnerable path.
  • Monitor RDP traffic for anomalous or oversized ATR length fields and investigate any suspicious activity.

Generated by OpenCVE AI on September 20, 2026 at 16:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description FreeRDP versions before 3.31.0 contain an out-of-bounds read vulnerability in smartcard response decoders that fail to validate ATR length fields against fixed inline arrays. Authenticated RDP clients can send oversized ATR lengths in PAKID_CORE_DEVICE_IOCOMPLETION responses to trigger reads past stack or heap objects, causing process termination.
Title FreeRDP before 3.31.0 Out-of-bounds Read via Smartcard ATR
First Time appeared Freerdp
Freerdp freerdp
Weaknesses CWE-125
CPEs cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*
Vendors & Products Freerdp
Freerdp freerdp
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T15:52:09.501Z

Reserved: 2026-09-15T11:07:01.913Z

Link: CVE-2026-91945

cve-icon Vulnrichment

Updated: 2026-09-15T15:52:05.990Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T16:17:46.657

Modified: 2026-09-24T12:13:45.970

Link: CVE-2026-91945

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-15T15:18:04Z

Links: CVE-2026-91945 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:45:07Z

Weaknesses