Description
FreeRDP before 3.31.0 fails to validate client-supplied DesktopWidth and DesktopHeight values during GCC negotiation, allowing remote attackers to crash the server. Attackers can send crafted RDP packets with zero or oversized dimensions to trigger division-by-zero or assertion failures in multifragment update capability calculations, terminating the server process.
Published: 2026-09-15
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

FreeRDP fails to validate client‑supplied DesktopWidth and DesktopHeight values during GCC negotiation, allowing an attacker to craft RDP packets with zero or oversized dimensions that trigger division‑by‑zero or assertion failures in multifragment update capability calculations. The result is a crash of the server process, producing a denial of service to any client and potentially disrupting all RDP sessions to the server. This vulnerability is classified as CWE-369.

Affected Systems

FreeRDP installations prior to version 3.31.0, i.e., every FreeRDP instance using a server component that accepts remote RDP connections, are vulnerable to a crash when receiving malformed DesktopWidth and DesktopHeight values during GCC negotiation.

Risk and Exploitability

The CVSS score of 8.2 indicates a high severity with availability impact. The EPSS score is <1%, the KEV, so the public exploitation likelihood remains unclear. The attack vector is remote through an RDP connection, as the flaw requires an attacker to send modified RDP packets during the initial negotiation. If connected to a public network or an untrusted network, an adversary can trigger the crash by sending crafted packets.

Generated by OpenCVE AI on September 20, 2026 at 16:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade FreeRDP to version 3.31.0 or later, ensuring the bug fix is applied.
  • Restrict RDP access to the server by enforcing network‑level authentication or firewall rules, limiting connections to trusted hosts only.
  • Monitor server logs for unexpected crashes and enforce strict input validation or packet filtering to reject RDP packets with zero or excessively large desktop dimensions.

Generated by OpenCVE AI on September 20, 2026 at 16:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description FreeRDP before 3.31.0 fails to validate client-supplied DesktopWidth and DesktopHeight values during GCC negotiation, allowing remote attackers to crash the server. Attackers can send crafted RDP packets with zero or oversized dimensions to trigger division-by-zero or assertion failures in multifragment update capability calculations, terminating the server process.
Title FreeRDP before 3.31.0 Denial of Service via Desktop Dimensions
First Time appeared Freerdp
Freerdp freerdp
Weaknesses CWE-369
CPEs cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*
Vendors & Products Freerdp
Freerdp freerdp
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T15:54:42.025Z

Reserved: 2026-09-15T11:07:34.398Z

Link: CVE-2026-91955

cve-icon Vulnrichment

Updated: 2026-09-15T15:54:38.299Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T16:17:49.963

Modified: 2026-09-24T12:16:48.413

Link: CVE-2026-91955

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-15T15:18:11Z

Links: CVE-2026-91955 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:30:18Z

Weaknesses