FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTION_SHOW_PROTOCOL is enabled. Authenticated clients can queue oversized channel messages that cause buffer underflow and corrupt heap memory including live pointers, potentially enabling code execution.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 15 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTION_SHOW_PROTOCOL is enabled. Authenticated clients can queue oversized channel messages that cause buffer underflow and corrupt heap memory including live pointers, potentially enabling code execution. | |
| Title | FreeRDP before 3.31.0 Out-of-bounds Write via SHOW_PROTOCOL | |
| First Time appeared |
Freerdp
Freerdp freerdp |
|
| Weaknesses | CWE-191 | |
| CPEs | cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Freerdp
Freerdp freerdp |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T16:03:29.434Z
Reserved: 2026-09-15T11:07:01.913Z
Link: CVE-2026-91948
No data.
Status : Received
Published: 2026-09-15T16:17:48.503
Modified: 2026-09-15T16:17:48.503
Link: CVE-2026-91948
No data.
OpenCVE Enrichment
No data.
Weaknesses