Description
FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values from MSG_SNDIN_OPEN messages. Attackers can supply crafted FramesPerPacket values that cause AudioQueueAllocateBuffer size computation to wrap, resulting in undersized buffer allocation and potential out-of-bounds access.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-bounds buffer access via integer overflow
Action: Upgrade immediately
AI Analysis

Impact

FreeRDP before version 3.31.0 contains an integer overflow in its audin Apple backend when handling FramesPerPacket values supplied in MSG_SNDIN_OPEN messages. The overflow causes the AudioQueueAllocateBuffer size calculation to wrap, resulting in an undersized buffer allocation. This flaw exposes the application to potential out-of-bounds reads or writes (CWE‑131 and CWE‑787), which can lead to crashes or memory corruption in the process handling audio data.

Affected Systems

FreeRDP versions earlier than 3.31.0 that include the audin Apple backend are affected. The vulnerability is fixed in FreeRDP 3.31.0 and later. Users should verify that their FreeRDP installation does not enable the audin Apple backend if they cannot upgrade immediately.

Risk and Exploitability

The CVSS base score of 5.3 indicates moderate severity. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote: an attacker who can act as an RDP server to a vulnerable FreeRDP client could send crafted MSG_SNDIN_OPEN messages. While no publicly disclosed exploitation code exists, the memory corruption introduced by an out-of-bounds access could be leveraged by a determined adversary to destabilize or compromise the target system if they control the audio payload.

Generated by OpenCVE AI on September 20, 2026 at 17:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade FreeRDP to version 3.31.0 or later to remove the integer overflow flaw.
  • If an upgrade is not feasible, disable or remove the audin Apple backend, or configure the server to reject or limit MSG_SNDIN_OPEN messages from untrusted clients.
  • Implement input validation to ensure FramesPerPacket values remain within a safe numeric range before performing buffer size calculations.

Generated by OpenCVE AI on September 20, 2026 at 17:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values from MSG_SNDIN_OPEN messages. Attackers can supply crafted FramesPerPacket values that cause AudioQueueAllocateBuffer size computation to wrap, resulting in undersized buffer allocation and potential out-of-bounds access.
Title FreeRDP before 3.31.0 Integer Overflow via audin Apple backends
First Time appeared Freerdp
Freerdp freerdp
Weaknesses CWE-131
CPEs cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*
Vendors & Products Freerdp
Freerdp freerdp
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T14:58:43.285Z

Reserved: 2026-09-15T11:08:44.670Z

Link: CVE-2026-91962

cve-icon Vulnrichment

Updated: 2026-09-17T14:58:35.682Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T16:17:51.763

Modified: 2026-09-23T20:04:04.910

Link: CVE-2026-91962

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-15T15:18:15Z

Links: CVE-2026-91962 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T17:15:17Z

Weaknesses
  • CWE-131

    Incorrect Calculation of Buffer Size

  • CWE-787

    Out-of-bounds Write