Heap-based buffer overflow in FreeRDP - #VU138641
Published: July 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to integer overflow leading to a heap-based buffer overflow in the Audio Input Redirection virtual channel ALSA backend when processing a crafted FramesPerPacket value in MSG_SNDIN_OPEN or MSG_SNDIN_FORMATS messages. A remote attacker can send a specially crafted RDP server message to execute arbitrary code.
User interaction is required to connect to a malicious or compromised RDP server with audio input redirection enabled.