Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the URBDRC channel's func_get_ep_desc function that indexes interface arrays by position instead of protocol field InterfaceNumber. A malicious RDP server can send a crafted SELECT_CONFIGURATION message with permuted InterfaceNumber values to read past allocated heap memory and crash the client. | |
| Title | FreeRDP before 3.31.0 Out-of-Bounds Read via URBDRC | |
| First Time appeared |
Freerdp
Freerdp freerdp |
|
| Weaknesses | CWE-125 | |
| CPEs | cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Freerdp
Freerdp freerdp |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T15:18:11.941Z
Reserved: 2026-09-15T11:07:34.398Z
Link: CVE-2026-91956
No data.
Status : Received
Published: 2026-09-15T16:17:50.500
Modified: 2026-09-15T16:17:50.500
Link: CVE-2026-91956
No data.
OpenCVE Enrichment
No data.
-
CWE-125
Out-of-bounds Read