Description
FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks with more region rectangles than preallocated worker array size. A malicious RDP server can send crafted AVC444 graphics updates causing the threaded decode path to loop indefinitely, consuming CPU and preventing normal client operation.
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

FreeRDP versions before 3.31.0 have a flaw in the pool_decode_rect function that causes an infinite loop when decoding AVC444 metablocks containing more region rectangles than the size of a pre‑allocated worker array. A malicious RDP server can send crafted graphics updates that exhaust CPU resources, causing the client to hang. The flaw involves insufficient bounds checking (CWE-606) and results in an infinite loop (CWE-835).

Affected Systems

The vulnerability affects all FreeRDP deployments running any version prior to 3.31.0. The affected product is FreeRDP from the FreeRDP project. No specific sub‑components or modules other than the pool_decode_rect path are listed as affected.

Risk and Exploitability

The CVSS score of 7.1 reflects a high severity denial‑of‑service potential. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed exploitation yet. The likely attack vector is a remote RDP connection: an attacker must be able to act as a server that issues malicious AVC444 updates. The exploit requires no local privileges or code execution; it merely forces the client to hang due to prolonged CPU consumption during graphic decoding.

Generated by OpenCVE AI on September 20, 2026 at 16:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade FreeRDP to version 3.31.0 or later to remove the pool_decode_rect flaw.
  • Restrict RDP connections to trusted hosts or use firewalls to block untrusted RDP traffic‑limiting or timeout mechanisms when receiving graphic updates from unknown servers.
  • Implement server‑side timeouts or client‑side CPU usage limits for graphic decoding to prevent prolonged CPU consumption during malicious updates.

Generated by OpenCVE AI on September 20, 2026 at 16:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-606
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks with more region rectangles than preallocated worker array size. A malicious RDP server can send crafted AVC444 graphics updates causing the threaded decode path to loop indefinitely, consuming CPU and preventing normal client operation.
Title FreeRDP before 3.31.0 Denial of Service via pool_decode_rect
First Time appeared Freerdp
Freerdp freerdp
Weaknesses CWE-835
CPEs cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*
Vendors & Products Freerdp
Freerdp freerdp
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T14:55:14.149Z

Reserved: 2026-09-15T11:07:34.398Z

Link: CVE-2026-91952

cve-icon Vulnrichment

Updated: 2026-09-17T14:54:58.621Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T16:17:49.490

Modified: 2026-09-24T12:15:29.993

Link: CVE-2026-91952

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-15T15:18:09Z

Links: CVE-2026-91952 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T17:00:13Z

Weaknesses
  • CWE-606

    Unchecked Input for Loop Condition

  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')