Where
-Infinity
0
Severity
8.7
EPSS
0.55%
Buffer Overflow
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

FreeRDP versions before 3.31.0 contain a heap-based buffer overflow in negosendnegotiationrequest when processing Server Redirection PDU messages with attacker-controlled LoadBalanceInfo fields. A malicious RDP server can trigger the overflow by sending an arbitrary-length field that gets written to a fixed 512-byte buffer without validation, causing client crashes or potential code execution when chained with memory disclosure.

First published (updated )
Severity
7.1
EPSS
0.64%
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.

First published (updated )
Severity
5.3
EPSS
0.24%
Integer Overflow
AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values from MSGSNDINOPEN messages. Attackers can supply crafted FramesPerPacket values that cause AudioQueueAllocateBuffer size computation to wrap, resulting in undersized buffer allocation and potential out-of-bounds access.

First published (updated )
Severity
7.1
EPSS
0.35%
AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

FreeRDP before 3.31.0 contains a denial-of-service vulnerability in the URBDRC control-transfer request path that fails to validate OutputBufferSize before forwarding to the libusb backend. A malicious RDP server can send a control-transfer request with OutputBufferSize set to 65536, triggering a reachable assertion that terminates the client process.

First published (updated )
Severity
7.1
EPSS
0.44%
Integer Overflow, Double Free
AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's StreamEnsureRemainingCapacity function that allows remote attackers to cause denial of service. A malicious RD Gateway peer can send a WebSocket Ping frame with a crafted 64-bit extended payload length to trigger integer wraparound, resulting in a double free that crashes the FreeRDP client during connection.

First published (updated )
Severity
7.1
EPSS
0.35%
AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

FreeRDP before 3.31.0 contains a buffer over-read vulnerability in the rtsreadresult function within the RPC gateway transport parser. Attackers can send a malicious BINDACK PDU with a truncated result entry to trigger an out-of-bounds read causing process abort.

First published (updated )
Severity
6.9
EPSS
0.20%
AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H

FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xfdetectmonitors. Attackers can craft a malicious RDP file with an out-of-range selectedmonitors value to trigger out-of-bounds heap read and write operations when opened in xfreerdp.

First published (updated )
Severity
2.3
EPSS
0.33%
Use After Free
AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L

FreeRDP before 3.31.0 contains a use-after-free vulnerability in the smartcard RDPDR device handler when worker thread creation fails after device registration. Attackers can trigger thread creation failure during channel setup to cause device pointer deallocation while devman retains a reference, leading to crash or code execution.

First published (updated )
Severity
7.1
EPSS
0.35%
AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the URBDRC channel's funcgetepdesc function that indexes interface arrays by position instead of protocol field InterfaceNumber. A malicious RDP server can send a crafted SELECTCONFIGURATION message with permuted InterfaceNumber values to read past allocated heap memory and crash the client.

First published (updated )
Severity
8.2
EPSS
0.45%
Divide by Zero
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

FreeRDP before 3.31.0 fails to validate client-supplied DesktopWidth and DesktopHeight values during GCC negotiation, allowing remote attackers to crash the server. Attackers can send crafted RDP packets with zero or oversized dimensions to trigger division-by-zero or assertion failures in multifragment update capability calculations, terminating the server process.

First published (updated )
Severity
7.1
EPSS
0.35%
Null Pointer Dereference
AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

FreeRDP before 3.31.0 contains a null pointer dereference vulnerability in gdisurfacebits when processing Surface Bits commands with NSCodec codec ID. A malicious RDP server can crash a FreeRDP client by sending a crafted Surface Bits command claiming to use NSCodec, even when the codec is disabled.

First published (updated )
Severity
7.1
EPSS
0.42%
Buffer Overflow
AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

FreeRDP versions before 3.31.0 contain a heap buffer overflow vulnerability in negosendnegotiationrequest() that fails to validate the LBLOADBALANCEINFO field length before writing to a fixed 512-byte buffer. A malicious RDP server or man-in-the-middle can send a Server Redirection PDU with an oversized LBLOADBALANCEINFO value to overflow the buffer with attacker-controlled content, causing denial of service or heap corruption before authentication completes.

First published (updated )
Severity
7.1
EPSS
0.35%
AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pooldecoderect function when decoding AVC444 metablocks with more region rectangles than preallocated worker array size. A malicious RDP server can send crafted AVC444 graphics updates causing the threaded decode path to loop indefinitely, consuming CPU and preventing normal client operation.

First published (updated )
Severity
7.1
EPSS
0.35%
AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urbsendcurrentframenumberresult() function. A malicious RDP server can send a crafted 28-byte USB redirection message to trigger a 4-byte write past the allocated 16-byte buffer, causing denial of service when verbose asserts are enabled.

First published (updated )
Severity
7.1
EPSS
0.45%
AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the rdpdrdumppacket function due to 32-bit unsigned integer wraparound in buffer bounds validation. A malicious RDP server can send a crafted RDPDR packet with computerNameLen set to 0xFFFFFFF0 to bypass bounds checks and trigger memory reads past the packet buffer, causing client crashes or heap disclosure in logs.

First published (updated )
Severity
9.2
EPSS
0.45%
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N

FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, receive negotiation failures, then complete TLS handshake and enter RDSTLS to bypass pre-authentication transport restrictions.

First published (updated )
Severity
7.7
EPSS
0.65%
Integer Underflow
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNELOPTIONSHOWPROTOCOL is enabled. Authenticated clients can queue oversized channel messages that cause buffer underflow and corrupt heap memory including live pointers, potentially enabling code execution.

First published (updated )
Severity
7.1
EPSS
0.43%
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fixed 340-byte wire format. Attackers can receive uninitialized heap memory including live pointers and GLib function addresses transmitted in the PDU, defeating heap ASLR and disclosing the GLib module base address.

First published (updated )
Severity
7.1
EPSS
0.57%
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

FreeRDP versions before 3.31.0 contain an out-of-bounds read vulnerability in smartcard response decoders that fail to validate ATR length fields against fixed inline arrays. Authenticated RDP clients can send oversized ATR lengths in PAKIDCOREDEVICEIOCOMPLETION responses to trigger reads past stack or heap objects, causing process termination.

First published (updated )
Severity
5.3
AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L

FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the generalChromaV1ToYUV444 function during AVC444 chroma plane reconstruction. A malicious RDP server can craft a RFXAVC444BITMAPSTREAM with specific frame geometry to trigger an out-of-bounds memory read past the allocated luma plane.

First published (updated )
Severity
7.1
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uninitialized heap memory in Save Session Info PDU reserved padding fields. Three PDU writers in libfreerdp/core/info.c (rdpwritelogoninfov2, rdpwritelogoninfoplain, and rdpwritelogoninfoex) use StreamSeek instead of StreamZero for reserved pad bytes (up to 576 bytes), leaving previously freed heap contents in the outgoing PDU. Because the send buffer is allocated with malloc (not zeroed), stale heap data — which may include cleartext credentials from prior sessions — can be sent to the receiving peer. FreeRDP-based servers using rdpUpdate::SaveSessionInfo and freerdp-proxy (which forwards these PDUs) are affected, allowing disclosure of server/proxy process memory to a downstream client.

First published (updated )

FreeRDP 3.31.0 (2026-08-26) fixes 5 vulnerabilities in FreeRDP's server role that Bynario reported, as well as 17 other security issues. We were able to demonstrate that 3 of the issues could be chained to achieve pre-auth remote code execution, however we believe exposure to this specific chain is limited (more detail below).

Affected projects include those that embed FreeRDP as an RDP server, including GNOME Remote Desktop and KDE krdp. These are not typically enabled by default, so affected machines are those that have been configured by an administrator to use an affected remote desktop / login service. Client-role FreeRDP is not affected by any of the 5 issues we reported.

Remediation: upgrade to FreeRDP 3.31.0. There is no 3.30.x point release, so distributions on 3.30.0 or earlier need the 3.31.0 rebase or their own backports.

The Vulnerabilities ===================

Below are summaries of the reported vulnerabilities. Note 2 through 5 require an authenticated RDP session. Typically this is post-authentication, however for remote login modes, 1 can be used to bypass authentication and setup an RDP connection (used to render the login screen prior to local user auth), making the other issues reachable.

1. Negotiation failure is not terminal (GHSA-x7v6-xfx3-52j6)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N (9.3, Critical)

A server that rejects the client's protocol offer sends the failure PDU, does not close the socket, and then bit-tests the failure code as if it were a protocol selection. Every failure code the server can emit collides with a protocol bit, so an unauthenticated peer that ignores the rejection is dispatched into a security mechanism the server disabled and the client never requested. Which one depends on the server's policy: an NLA-only server enters RDSTLS, an RDP-enabled server enters NLA, otherwise TLS.

Impact: pre-authentication security-mechanism selection bypass.

Affected: 3.0.0-beta1 through 3.30.0.

2. RDPGFX ResetGraphics discloses uninitialised heap (GHSA-r7jx-j9h7-j4xj)

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N (6.5, Medium)

The server serialises a fixed 340-byte PDU but seeks over the trailing padding instead of writing it, and sends the whole thing from an uninitialised buffer. A one-monitor reset discloses 300 bytes of stale heap to the peer.

Impact: information disclosure. Demonstrated remote leak of heap + module pointers.

Affected: 3.x through 3.30.0.

3. Channel PDU tracker offset desync (GHSA-9jcm-x588-gh26)

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H (7.5, High)

An oversized static-virtual-channel message desynchronises the reassembler's offset; a later size calculation underflows and writes eight attacker-controlled bytes onto a live function-pointer-bearing object in the same allocation, which is then dereferenced immediately.

Impact: build-dependent. On a default upstream build the process aborts before the write occurs, so it is a remote denial of service. The write only happens on builds with NDEBUG and WITHVERBOSEWINPRASSERT=OFF; Debian, Ubuntu, Fedora and Arch all ship this config. There it is a controlled 8-byte overwrite at a fixed, immediately-used address. Requires a channel opened with CHANNELOPTIONSHOWPROTOCOL whose poll loop survives a failed poll; in the tree that is device redirection.

Affected: 3.28.0, 3.29.0 and 3.30.0 only.

4. DRDYNVC parser uses a borrowed channel pointer after free (GHSA-6mpx-c8rj-whj5)

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H (7.5, High)

The dynamic-virtual-channel lookup returns a pointer from a synchronised table but drops the lock before returning and takes no reference, so a concurrent close on the channel's own worker thread frees the object under the parser.

Impact: use-after-free. Confirmed under AddressSanitizer; the directly demonstrated impact is availability loss.

Affected: 3.x through 3.30.0.

5. Smartcard ATR lengths are not bounded to their arrays (GHSA-q65v-4w7q-hx3r)

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (6.5, Medium)

Two server-side smartcard response decoders accept a client-supplied ATR length without checking it against the fixed 32- and 36-byte arrays that hold it, and pass it to consumers that trust it.

Impact: out-of-bounds read; potential denial of service. No information disclosure.

Affected: 3.28.0, 3.29.0 and 3.30.0.

Exposure ========

The table below shows which applications using FreeRDP's server role are affected by which issue (using the indices above). cfg means reachability depends on a specific config:

1 2 3 4 5 GNOME Remote Desktop yes yes 51.beta yes 51.beta KDE krdp yes yes no no no Weston RDP backend cfg no no no no freerdp-shadow-cli cfg yes no yes no freerdp-proxy cfg no no no no sfreerdp (sample server) cfg no no yes no

The chain we demonstrated uses issues 1, 2 and 3. Only GNOME Remote Desktop (GRD) 51 pre-release is affected by all three. More specifically GRD 51 pre-release introduces the channel required to reach issue 3's out-of-bounds write. As a result, only distributions shipping pre-release GRD (and affected FreeRDP) are confirmed to be affected by the full chain. As of writing, this includes Fedora 45 & rawhide, Arch's gnome-unstable and CentOS Stream 11.

Furthermore, issue 1's impact varies depending on GNOME Remote Desktop's mode:

- Remote Login: bypass the system-wide authentication used to setup an RDP connection (to reach the login screen). - Screen Sharing and headless: the same transition, but the authorization callback then queries an authentication context that does not exist and the daemon dies. Pre-authentication remote denial of service of the logged-in user's session daemon.

As a result, the chain we demonstrated using these issues is limited to bleeding-edge releases using GRD's Remote Login mode (I imagine this is a small pool!). However, it's only the post-authentication steps that have the GRD pre-release requirements. The authentication bypass, issue 1, which exposes the rich RDP attack surface has very wide coverage (e.g. Ubuntu 24.04 LTS onwards) and may be chained with other n-day or 0-day issues to similar effect.

References ==========

FreeRDP 3.31.0 https://github.com/FreeRDP/FreeRDP/releases/tag/3.31.0 Issue 1 https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-x7v6-xfx3-52j6 Issue 2 https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-r7jx-j9h7-j4xj Issue 3 https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-9jcm-x588-gh26 Issue 4 https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-6mpx-c8rj-whj5 Issue 5 https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-q65v-4w7q-hx3r

Note: CVE identifiers are still pending assignment.

Credit ======

I would like to shout out @akallabeth for maintaining an awesome project and handling our security reports extremely fast.

These issues were found and validated by Bynario Atlas, an AI automated pipeline, while auditing FreeRDP 3.30.0. Reports were reviewed & submitted by myself (Samuel Page / sam4k).

We'll share technical details on the RCE chain on our blog, https://bynar.io/blog , after folks have had time to patch up.

Severity
4

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.29.0, planardecompressplanerle and planardecompressplanerleonly in libfreerdp/codec/planar.c verify that a control byte exists but do not verify that the source buffer contains the zero to fifteen raw bytes declared by that control byte. A malicious RDP server can send a truncated planar bitmap or surface update whose final control byte claims additional raw bytes, causing the decoder to read beyond pSrcData while processing a color plane. This can crash the client and may disclose adjacent memory. This issue is fixed in version 3.29.0.

First published (updated )
Severity
7

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, freerdpdspdecodeopus in libfreerdp/codec/dsp.c calls StreamEnsureRemainingCapacity on context->common.buffer even though opusdecode writes decoded PCM into the caller-supplied out stream. A malicious RDP server that negotiates WAVEFORMATOPUS with a client built with WITHOPUS enabled and WITHDSPFFMPEG disabled can make libopus write a large decoded frame beyond the 4096-byte StreamPoolTake destination used by channels/rdpsnd/client/rdpsndmain.c. This can corrupt the client heap, crash the client, and may permit code execution. This issue is fixed in version 3.28.0.

First published (updated )
Severity
4

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsndserverrecvformats in channels/rdpsnd/server/rdpsndmain.c frees context->clientformats on a malformed Client Audio Formats PDU without clearing the owning pointer or numclientformats. An authenticated RDP client can trigger an error such as a cbSize larger than the remaining record, leave the dangling pointer in the server context, and cause rdpsndservercontextfree to free the same allocation again at session teardown. This reliably terminates the server and can create allocator-dependent heap corruption. This issue is fixed in version 3.28.0.

First published (updated )
Severity
4

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.29.0, planardecompressplanerle and planardecompressplanerleonly in libfreerdp/codec/planar.c verify that a control byte exists but do not verify that the source buffer contains the zero to fifteen raw bytes declared by that control byte. A malicious RDP server can send a truncated planar bitmap or surface update whose final control byte claims additional raw bytes, causing the decoder to read beyond pSrcData while processing a color plane. This can crash the client and may disclose adjacent memory. This issue is fixed in version 3.29.0.

1 / 2
Source: Red Hat
First published (updated )
Severity
7.7
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, freerdpdspdecodeopus in libfreerdp/codec/dsp.c calls StreamEnsureRemainingCapacity on context->common.buffer even though opusdecode writes decoded PCM into the caller-supplied out stream. A malicious RDP server that negotiates WAVEFORMATOPUS with a client built with WITHOPUS enabled and WITHDSPFFMPEG disabled can make libopus write a large decoded frame beyond the 4096-byte StreamPoolTake destination used by channels/rdpsnd/client/rdpsndmain.c. This can corrupt the client heap, crash the client, and may permit code execution. This issue is fixed in version 3.28.0.

First published (updated )
Severity
7.1
Double Free
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsndserverrecvformats in channels/rdpsnd/server/rdpsndmain.c frees context->clientformats on a malformed Client Audio Formats PDU without clearing the owning pointer or numclientformats. An authenticated RDP client can trigger an error such as a cbSize larger than the remaining record, leave the dangling pointer in the server context, and cause rdpsndservercontextfree to free the same allocation again at session teardown. This reliably terminates the server and can create allocator-dependent heap corruption. This issue is fixed in version 3.28.0.

First published (updated )
Severity
6.5
Divide by Zero
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, an authenticated RDP client can advertise DVI ADPCM with nBlockAlign equal to 8 and nChannels equal to 2 to make the bs calculation in rdpsndserverselectformat in channels/rdpsnd/server/rdpsndmain.c equal zero. The subsequent outframes modulo bs operation raises SIGFPE and terminates the server-side rdpsnd channel process. This vulnerability fixed in 3.28.0.

First published (updated )
Severity
7.2
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP H.264 decoder backends can return YUV planes sized from the bitstream without comparing the decoded width and height to the RDPGFX surface dimensions used to validate region rectangles. A malicious RDP server can provide an AVC420 or AVC444 bitstream whose decoded frame is smaller than the negotiated surface, causing yuv420contextdecode and the YUV-to-RGB conversion paths to read beyond the decoder-owned planes in libfreerdp/codec/h264.c and the selected H.264 backend. This can disclose client memory or crash the client. This issue is fixed in version 3.27.0.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203