REDHAT-BUG-2510125: Buffer Overflow

Published Aug 2, 2026
·
Updated

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can supply a malicious FramesPerPacket value causing allocation size wraparound, resulting in heap-based buffer overflow on ALSA or denial of service on all platforms.

Affected Software

1 affected component
FreeRDP<3.29.0

Event History

Aug 2, 2026
Data Sourced
via Red Hat·01:01 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What does an attacker need to control to exploit this issue?

The attacker needs to operate or control an RDP server that can send a malicious FramesPerPacket value through the audio input redirection channel.

2

Which environments face heap-based buffer-overflow risk rather than only denial of service?

The heap-based buffer overflow is identified on the ALSA backend. The issue can cause denial of service on all affected platforms and audio backends.

3

Which FreeRDP versions need to be remediated?

FreeRDP versions before 3.29.0 are affected. Updating to 3.29.0 or later addresses the described vulnerable behavior.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203