REDHAT-BUG-2519826: High severity FreeRDP freerdp vulnerability

Published Aug 19, 2026
·
Updated

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, freerdpdspdecodeopus in libfreerdp/codec/dsp.c calls StreamEnsureRemainingCapacity on context->common.buffer even though opusdecode writes decoded PCM into the caller-supplied out stream. A malicious RDP server that negotiates WAVEFORMATOPUS with a client built with WITHOPUS enabled and WITHDSPFFMPEG disabled can make libopus write a large decoded frame beyond the 4096-byte StreamPoolTake destination used by channels/rdpsnd/client/rdpsndmain.c. This can corrupt the client heap, crash the client, and may permit code execution. This issue is fixed in version 3.28.0.

Affected Software

1 affected component
FreeRDP freerdp<3.28.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade FreeRDP (libfreerdp) to a version that resolves this vulnerability.

    Fixed in 3.28.0

Event History

Aug 19, 2026
Data Sourced
via Red Hat·06:17 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Which FreeRDP clients are exposed to this issue?

Clients using FreeRDP versions prior to 3.28.0 are affected when built with WITH_OPUS enabled and WITH_DSP_FFMPEG disabled. The vulnerable path is used when the client negotiates WAVE_FORMAT_OPUS with an RDP server.

2

What must an attacker control to exploit it?

An attacker needs to operate or control a malicious RDP server that a vulnerable client connects to. The server must negotiate Opus audio and provide a crafted frame large enough to overflow the client-side 4096-byte destination buffer.

3

What is the likely impact on an affected client?

A malicious server can corrupt the FreeRDP client heap and crash the client. The issue may also permit code execution on the client.

4

What should be done if immediate patching is not possible?

Avoid connecting vulnerable FreeRDP clients to untrusted RDP servers, especially where Opus audio may be negotiated. The available fixed version is 3.28.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203