Description
FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the rdpdr_dump_packet function due to 32-bit unsigned integer wraparound in buffer bounds validation. A malicious RDP server can send a crafted RDPDR packet with computerNameLen set to 0xFFFFFFF0 to bypass bounds checks and trigger memory reads past the packet buffer, causing client crashes or heap disclosure in logs.
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure and crash (Denial of Service)
Action: Apply Patch
AI Analysis

Impact

FreeRDP versions earlier than 3.31.0 contain an out‑of‑bounds read in the rdpdr_dump_packet routine. The flaw arises from a 32‑bit unsigned integer wraparound in buffer bounds validation. A crafted RDPDR packet with a computerNameLen value close to the maximum unsigned 32‑bit value can bypass the bounds check, allowing the client to read memory beyond the packet buffer. This may result in client crashes or the disclosure of heap contents in out‑of‑bounds read (CWE‑125).

Affected Systems

The affected product is FreeRDP (FreeRDP). All releases prior to version 3.31.0 are impacted. No specific sub‑versions are mentioned, so the entire pre‑3.31.0 series is at risk.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity. The EPSS score of less than 1% suggests that the likelihood of public exploitation is low at present. The vulnerability is not listed in CISA KEV, indicating no current known exploits. However, the flaw can be triggered remotely by a malicious RDP server that sends a specially crafted RDPDR packet, which would force the client to crash or leak sensitive data from the client’s heap.

Generated by OpenCVE AI on September 20, 2026 at 16:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update FreeRDP to version 3.31.0 or later to remove the bounds check vulnerability.
  • Configure the RDP client to accept connections only from trusted servers and apply network filtering to restrict untrusted RDP traffic.
  • Enable logging of out‑of‑bounds read attempts and monitor logs for anomalous memory references or crashes, then investigate any suspicious events immediately.

Generated by OpenCVE AI on September 20, 2026 at 16:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the rdpdr_dump_packet function due to 32-bit unsigned integer wraparound in buffer bounds validation. A malicious RDP server can send a crafted RDPDR packet with computerNameLen set to 0xFFFFFFF0 to bypass bounds checks and trigger memory reads past the packet buffer, causing client crashes or heap disclosure in logs.
Title FreeRDP before 3.31.0 Out-of-Bounds Read via UINT32 Wraparound
First Time appeared Freerdp
Freerdp freerdp
Weaknesses CWE-125
CPEs cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*
Vendors & Products Freerdp
Freerdp freerdp
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T15:54:08.073Z

Reserved: 2026-09-15T11:07:34.398Z

Link: CVE-2026-91950

cve-icon Vulnrichment

Updated: 2026-09-15T15:54:04.100Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T16:17:48.800

Modified: 2026-09-24T12:15:06.237

Link: CVE-2026-91950

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-15T15:18:07Z

Links: CVE-2026-91950 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:30:18Z

Weaknesses