CVE-2026-91952: FreeRDP before 3.31.0 Denial of Service via pool_decode_rect

Published Sep 15, 2026
·
Updated

FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pooldecoderect function when decoding AVC444 metablocks with more region rectangles than preallocated worker array size. A malicious RDP server can send crafted AVC444 graphics updates causing the threaded decode path to loop indefinitely, consuming CPU and preventing normal client operation.

Affected Software

1 affected component
FreeRDP freerdp<3.31.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade FreeRDP to a version that resolves this vulnerability.

    Fixed in 3.31.0
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Patch Denial of Service via pool_decode_rect

Event History

Sep 15, 2026
CVE Published
via MITRE·03:18 PM
Data Sourced
via MITRE·03:18 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

FreeRDP clients running a version before 3.31.0 are exposed when they connect to a malicious RDP server that can deliver crafted AVC444 graphics updates. The issue affects the threaded decode path.

2

What does an attacker need to exploit it?

An attacker needs to operate or control an RDP server that the vulnerable FreeRDP client connects to. No client privileges are required, but user interaction is required because the client must initiate or accept the connection.

3

What is the operational impact of successful exploitation?

The crafted update can cause pool_decode_rect to loop indefinitely, consuming CPU and preventing normal operation of the FreeRDP client. The provided information describes a denial of service and does not indicate confidentiality or integrity impact.

4

How can I remediate the issue?

Upgrade FreeRDP to version 3.31.0 or later. If upgrading cannot happen immediately, avoid connecting affected clients to untrusted RDP servers, particularly where AVC444 graphics updates may be supplied.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203