top of page
perceptive_background_267k.jpg

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends…

Published:

2 augustus 2026 om 00:00:00

Alert date:

2 augustus 2026 om 16:02:48

Source:

nvd.nist.gov

Click to open the original link from this advisory

Network Infrastructure, Enterprise Applications

FreeRDP versions before 3.29.0 are affected by integer overflow vulnerabilities in the audio input redirection channel (audin). The issue spans multiple backends including ALSA, sndio, WinMM, and OpenSL ES, all of which fail to properly validate the FramesPerPacket parameter received from RDP servers. An attacker controlling a malicious RDP server can supply a crafted FramesPerPacket value that causes allocation size wraparound. On ALSA, this results in a heap-based buffer overflow, which could potentially lead to arbitrary code execution. On all affected platforms, the vulnerability can cause denial of service. The fix is available in FreeRDP 3.29.0. Users are advised to upgrade immediately to mitigate the risk of exploitation in remote desktop scenarios.

Technical details

Mitigation steps:

Affected products:

FreeRDP

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page