These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities. The CVE record was published on 2026-09-15T16:17:51.907Z and has n [truncated]
CVE-2026-91962 FreeRDP Integer Overflow: FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values from MSG_SNDIN_OPEN messages. This can lead to undersized buffer allocation and potential out-of-bounds access. Defenders and administrators using FreeRDP should assess exposure and prioritize patching to version 3.31.0 or later. The vulnerability h [truncated]
A denial-of-service vulnerability exists in FreeRDP before version 3.31.0. The vulnerability is located in the URBDRC control-transfer request path and occurs when the OutputBufferSize is not validated before being forwarded to the libusb backend. A malicious RDP server can exploit this by sending a control-transfer request with OutputBufferSize set to 65536, which triggers a reachable assertion that term [truncated]
CVE-2026-91959 FreeRDP Buffer Over-read Vulnerability. FreeRDP before 3.31.0 contains a buffer over-read vulnerability in the rts_read_result function within the RPC gateway transport parser. Attackers can send a malicious BIND_ACK PDU with a truncated result entry to trigger an out-of-bounds read causing process abort. Defenders should assess exposure and prioritize patching to prevent potential process [truncated]
CVE-2026-91956 is a high-severity vulnerability in FreeRDP before version 3.31.0, allowing for an out-of-bounds read via the URBDRC channel's func_get_ep_desc function. A malicious RDP server can exploit this by sending a crafted SELECT_CONFIGURATION message, potentially crashing the client. Defenders should assess exposure, prioritize remediation, and verify client versions.
A vulnerability in FreeRDP versions before 3.31.0 allows a malicious RDP server to send a crafted USB redirection message, triggering an out-of-bounds write and causing denial of service when verbose asserts are enabled. The vulnerability affects FreeRDP deployments, and defenders should assess exposure and prioritize patching to prevent potential denial-of-service attacks. Affected deployments should rev [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-15T16:17:47.990Z and has not been modified since then. FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer. The serializer fails to initialize padding bytes in the fixed 340-byte wire format, allowing attackers to receive [truncated]
CVE-2026-63652 FreeRDP vulnerability debrief. FreeRDP is a free implementation of the Remote Desktop Protocol. The vulnerability exists in the rdpsnd_server_recv_formats function in channels/rdpsnd/server/rdpsnd_main.c, where a malformed Client Audio Formats PDU can cause a dangling pointer and lead to a crash or potentially heap corruption. This issue is fixed in version 3.28.0. Defenders responsible for [truncated]
A vulnerability in FreeRDP, a free implementation of the Remote Desktop Protocol, can cause heap corruption and potentially allow for code execution. This issue is fixed in version 3.28.0. The vulnerability exists in the freerdp_dsp_decode_opus function in libfreerdp/codec/dsp.c, where a malicious RDP server can exploit this vulnerability by negotiating WAVE_FORMAT_OPUS with a client built with WITH_OPUS [truncated]
CVE-2026-63117 FreeRDP Denial of Service Vulnerability. An authenticated RDP client can trigger a denial of service in FreeRDP prior to version 3.28.0 by advertising DVI ADPCM with specific parameters, causing a SIGFPE and terminating the rdpsnd channel process. System administrators and security teams should assess exposure and apply patches. This vulnerability affects FreeRDP implementations and require [truncated]
The CVE-2026-55648 vulnerability affects FreeRDP, a free implementation of the Remote Desktop Protocol, prior to version 3.27.0. This vulnerability involves an integer wrap in the calculation of image data size, allowing a malicious RDP server to potentially execute arbitrary code on affected clients. Organizations should review and update their installations to prevent potential exploitation. The CVE rec [truncated]
A vulnerability in FreeRDP, a free implementation of the Remote Desktop Protocol, allows a malicious RDP server to crash the client and potentially disclose adjacent heap data. The issue, fixed in version 3.27.0, involves improper index checking in the glyph_cache_get function. This vulnerability can have significant impacts on organizations using FreeRDP clients, particularly those in environments where [truncated]
A vulnerability in FreeRDP, a free implementation of the Remote Desktop Protocol, can allow a malicious TS Gateway to send a crafted response that may crash the client or potentially permit code execution through heap corruption. This issue is caused by rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c not properly ensuring the response reassembly stream capacity using only the server-decla [truncated]
A vulnerability in FreeRDP, a free implementation of the Remote Desktop Protocol, allows a malicious gateway to potentially crash the client and may permit code execution through attacker-controlled heap corruption. This issue is caused by the lack of bounding of the server-controlled max_xmit_frag value in libfreerdp/core/gateway/rpc_bind.c. A malicious gateway can advertise a large value and send a resp [truncated]
A vulnerability in FreeRDP's H.264 decoder backends can cause memory disclosure or client crashes when connecting to a malicious RDP server. The issue is fixed in version 3.27.0. This vulnerability allows a malicious RDP server to provide an AVC420 or AVC444 bitstream whose decoded frame is smaller than the negotiated surface, causing yuv420_context_decode and the YUV-to-RGB conversion paths to read beyon [truncated]
A FreeRDP client vulnerability allows a malicious RDP server to cause a client crash and potentially permit code execution through heap corruption when negotiating RDPGFX AVC444 with an H.264 decoder backend. The vulnerability arises from a 32-bit multiplication in avc444_ensure_buffer within libfreerdp/codec/h264.c, leading to undersized buffer allocation. Defenders should assess exposure and prioritize [truncated]
CVE-2026-73242 is a high-severity vulnerability in FreeRDP, a free implementation of the Remote Desktop Protocol. The vulnerability exists in the kerberos_DecryptMessage function, which fails to bound the peer-controlled GSS Wrap-token EC field before using it with RRC in IOV pointer offsets. This allows a malicious RDP peer to trigger out-of-bounds reads and in-place writes during CredSSP/NLA Kerberos de [truncated]
CVE-2026-73241 is a high-severity vulnerability in FreeRDP, a free implementation of the Remote Desktop Protocol. The issue allows an unauthenticated client to bypass certain authentication checks due to improper handling of RDSTLS_TYPE_CAPABILITIES PDU in the server-side RDSTLS implementation. This vulnerability is fixed in FreeRDP version 3.30.0.
CVE-2026-68580 FreeRDP Integer Overflow. FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends. These vulnerabilities occur because the FramesPerPacket parameter from RDP servers is not validated. An attacker can supply a malicious FramesPerPacket value, causing allocation size wraparound, which resu [truncated]
A heap-based buffer overflow vulnerability exists in FreeRDP before version 3.30.0 in the Windows clipboard client's CliprdrStream_Read function. This vulnerability allows a malicious or compromised RDP server to return an oversized CB_FILECONTENTS_RESPONSE, potentially causing an out-of-bounds write of attacker-controlled data into the paste consumer's heap buffer when a user pastes server-offered clipbo [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T13:17:00.250Z and has not been modified since then. CVE-2026-67306 is an out-of-bounds read vulnerability in FreeRDP versions 3.28.0 and earlier. The issue is fixed in FreeRDP 3.29.0. Evidence is limited; further verification is recommended. Organizations should verify their deployments, review o [truncated]
The FreeRDP Windows client before version 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel. This vulnerability occurs when processing CLIPRDR_FILE_CONTENTS_RESPONSE PDUs without validating the server-provided size against the destination buffer. A malicious RDP server can exploit this by sending a response with a data payload significantly larger than requested, leadin [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T13:16:59.970Z and has not been modified since then. FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails. Attackers can send malformed smartcard IRP requests with non-zero cReaders and truncated reader [truncated]
FreeRDP versions prior to 3.29.0 are affected by a divide-by-zero vulnerability in the rdpecam camera redirection client. The vulnerability occurs when a malicious or compromised RDP server sends a StartStreamsRequest with FrameRateDenominator set to zero, causing an integer division by zero and termination of the FreeRDP client process. Users of FreeRDP versions prior to 3.29.0, especially those with cam [truncated]
FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders. The vulnerabilities occur when AsyncUpdate is enabled, causing update_message_PolygonSC() and update_message_PolygonCB() to allocate a fresh points array but copy point data from the address of the order structure instead of from polygonSC->points / po [truncated]
FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIL WINDOW_STATE_ORDER and NOTIFY_ICON_STATE_ORDER when AsyncUpdate is enabled. A malicious or compromised RDP server can exploit these vulnerabilities by sending crafted update orders, potentially causing memory corruption or a client crash. The CVE record was published on 2026-08-01T13:1 [truncated]
CVE-2026-67299 is a client-side heap use-after-free vulnerability in FreeRDP before version 3.29.0. The vulnerability occurs in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled. A malicious RDP server can trigger the use-after-free by sending a crafted RAIL Window Alternate Secondary Order with WINDOW_ORDER_ICON, leading to memory corruption and client crashes. FreeRDP user [truncated]
FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler. This vulnerability is triggered when processing a RAIL PDU header, where the code subtracts RAIL_PDU_HEADER_LENGTH from the peer-controlled orderLength field without first verifying orderLength is at least the header length. Consequently, for orderLength values 0..3, an unsigned integer underflow oc [truncated]
FreeRDP before 3.29.0 is vulnerable to a resource exhaustion attack via chunked HTTP responses. A malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resources without triggering the configured size limit. This vulnerability requires verification of FreeRDP versions and patch application to prevent exploitation. Defenders should assess exposure and prioritize [truncated]
A denial of service vulnerability exists in FreeRDP before version 3.29.0 in the RDPEI server channel handler. The vulnerability occurs because the handler fails to validate the maximum PDU body length before stream allocation. A malicious RDP client can exploit this by sending a header-only RDPEI message with a large declared body length, forcing excessive memory allocation on the server.