CVE-2026-91950: FreeRDP before 3.31.0 Out-of-Bounds Read via UINT32 Wraparound

Published Sep 15, 2026
·
Updated

FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the rdpdrdumppacket function due to 32-bit unsigned integer wraparound in buffer bounds validation. A malicious RDP server can send a crafted RDPDR packet with computerNameLen set to 0xFFFFFFF0 to bypass bounds checks and trigger memory reads past the packet buffer, causing client crashes or heap disclosure in logs.

Affected Software

1 affected component
FreeRDP freerdp<3.31.0

Event History

Sep 15, 2026
CVE Published
via MITRE·03:18 PM
Data Sourced
via MITRE·03:18 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker operating a malicious RDP server can exploit it against a FreeRDP client that connects to that server. The vector is network-based, but exploitation requires a user to initiate the RDP connection.

2

What is the impact on an affected client?

A crafted RDPDR packet can cause out-of-bounds reads, resulting in a client crash. Data from the heap may also be disclosed through logs.

3

Which versions need remediation?

FreeRDP versions before 3.31.0 are affected. Updating to 3.31.0 or later addresses the affected version range.

4

What can be done before updating?

Avoid connecting affected FreeRDP clients to untrusted or unknown RDP servers. Limit RDP connections to servers under administrative control, since the malicious packet is sent by the server.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203