Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTION_SHOW_PROTOCOL is enabled. Authenticated clients can queue oversized channel messages that cause buffer underflow and corrupt heap memory including live pointers, potentially enabling code execution. | |
| Title | FreeRDP before 3.31.0 Out-of-bounds Write via SHOW_PROTOCOL | |
| First Time appeared |
Freerdp
Freerdp freerdp |
|
| Weaknesses | CWE-191 | |
| CPEs | cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Freerdp
Freerdp freerdp |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T16:03:29.434Z
Reserved: 2026-09-15T11:07:01.913Z
Link: CVE-2026-91948
Updated: 2026-09-15T16:02:28.419Z
Status : Received
Published: 2026-09-15T16:17:48.503
Modified: 2026-09-15T17:17:41.080
Link: CVE-2026-91948
No data.
OpenCVE Enrichment
Updated: 2026-09-15T17:30:10Z
-
CWE-191
Integer Underflow (Wrap or Wraparound)