Description
FreeRDP versions before 3.31.0 contain a heap buffer overflow vulnerability in nego_send_negotiation_request() that fails to validate the LB_LOAD_BALANCE_INFO field length before writing to a fixed 512-byte buffer. A malicious RDP server or man-in-the-middle can send a Server Redirection PDU with an oversized LB_LOAD_BALANCE_INFO value to overflow the buffer with attacker-controlled content, causing denial of service or heap corruption before authentication completes.
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Heap buffer overflow that may cause denial of service or heap corruption before authentication
Action: Patch Immediately
AI Analysis

Impact

A heap buffer overflow exists in the nego_send_negotiation_request function of FreeRDP. The vulnerability occurs because the LB_LOAD_BALANCE_INFO field length is not verified prior to copying into a fixed 512-byte buffer. A malicious RDP server or attacker can send a Server Redirection PDU with an oversized field, causing the buffer to overflow and corrupt adjacent heap memory. The resulting overflow can lead to denial of service or heap corruption before the client or server authenticates.

Affected Systems

Any deployment of FreeRDP prior to version 3.31.0 that processes request negotiation is affected. The flaw resides in the FreeRDP client and server implementations and may impact clients or servers that receive Server Redirection PDU, confirming which FreeRDP version they are running to determine if the vulnerability applies.

Risk and Exploitability

The CVSS score of 7.1 reflects a moderate to high severity. EPSS score of < 1% indicates no public evidence of widespread exploitation, and the vulnerability is not listed in the CISA KEV catalog. The flaw is exploitable remotely via the RDP protocol; an unauthenticated attacker can craft a malicious Server Redirection PDU that triggers the overflow before authentication. If the overflow succeeds it can interrupt service or corrupt heap memory, potentially leading to application instability or further attacks.

Generated by OpenCVE AI on September 20, 2026 at 16:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to FreeRDP 3.31.0 or newer.
  • If an upgrade cannot be performed immediately, limit RDP connections to trusted networks by applying firewall or VPN restrictions.
  • Disable the Server Redirection (LB_LOAD_BALANCE_INFO) feature on both client and server if it is not needed.

Generated by OpenCVE AI on September 20, 2026 at 16:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description FreeRDP versions before 3.31.0 contain a heap buffer overflow vulnerability in nego_send_negotiation_request() that fails to validate the LB_LOAD_BALANCE_INFO field length before writing to a fixed 512-byte buffer. A malicious RDP server or man-in-the-middle can send a Server Redirection PDU with an oversized LB_LOAD_BALANCE_INFO value to overflow the buffer with attacker-controlled content, causing denial of service or heap corruption before authentication completes.
Title FreeRDP before 3.31.0 Heap Buffer Overflow via LB_LOAD_BALANCE_INFO
First Time appeared Freerdp
Freerdp freerdp
Weaknesses CWE-120
CPEs cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*
Vendors & Products Freerdp
Freerdp freerdp
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T16:01:36.361Z

Reserved: 2026-09-15T11:07:34.398Z

Link: CVE-2026-91953

cve-icon Vulnrichment

Updated: 2026-09-15T16:01:23.826Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T16:17:49.657

Modified: 2026-09-24T12:16:27.010

Link: CVE-2026-91953

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-15T15:18:09Z

Links: CVE-2026-91953 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:30:18Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')