Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-91964: FreeRDP client may crash or run code from rogue server
CVE-2026-91964 · published 25 days ago
Summary
Versions of FreeRDP up to 3.30 can be tricked by a malicious Remote Desktop server into writing more data than a small internal buffer can hold. This can cause the client program to stop working and, in rare cases, allow the attacker to execute their own code. Update FreeRDP to version 3.31 or later, or apply any patches provided by your Linux distribution, to stop the problem.
What to do
- Update debian freerdp3 to version 3.31.0+dfsg-1.
- Update canonical freerdp3 to version 3.31.0+dfsg-0ubuntu0.24.04.1.
- Update canonical freerdp3 to version 3.31.0+dfsg-0ubuntu0.26.04.1.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | freerdp | freerdp |
< 3.0.0 < 3.31.0 |
| Debian:12 | debian | freerdp2 | All versions |
| Debian:13 | debian | freerdp3 | All versions |
| Debian:14 | debian | freerdp3 |
< 3.31.0+dfsg-1 Fix: upgrade to 3.31.0+dfsg-1
|
| Ubuntu:16.04:LTS | canonical | freerdp | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | freerdp2 | All versions |
| Ubuntu:24.04:LTS | canonical | freerdp3 |
< 3.31.0+dfsg-0ubuntu0.24.04.1 Fix: upgrade to 3.31.0+dfsg-0ubuntu0.24.04.1
|
| Ubuntu:26.04:LTS | canonical | freerdp3 |
< 3.31.0+dfsg-0ubuntu0.26.04.1 Fix: upgrade to 3.31.0+dfsg-0ubuntu0.26.04.1
|
Original advisory text
FreeRDP 2.0.0 through 3.30.0 Heap Buffer Overflow via RoutingToken
FreeRDP versions before 3.31.0 contain a heap-based buffer overflow in nego_send_negotiation_request when processing Server Redirection PDU messages with attacker-controlled LoadBalanceInfo fields. A malicious RDP server can trigger the overflow by sending an arbitrary-length field that gets written to a fixed 512-byte buffer without validation, causing client crashes or potential code execution when chained with memory disclosure.
References
- https://security-tracker.debian.org/tracker/CVE-2026-91964 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-91964 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-91964 Third Party Advisory
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-2vf2-grvj-6g8x Vendor Advisory
- https://www.vulncheck.com/advisories/freerdp-2.0.0-through-3.30.0-heap-buffer-ov... Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/91xxx/CVE-2026-91964... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-91964 Vendor Advisory
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.9
Critical
Type
CWE-122Heap-based Buffer Overflow
Timeline
Published15 Sep 2026
Updated9 Oct 2026
First seen15 Sep 2026
Sources
CVE-2026-91964 · NVD
CVE-2026-91964 · MITRE
DEBIAN-CVE-2026-91964 · OSV
CVE-2026-91964 · OSV
GHSA-2vf2-grvj-6g8x · GHSA
UBUNTU-CVE-2026-91964 · OSV
Track software like this
Free during beta