Division by zero in FreeRDP - #VU146586
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to divide by zero in rdp_write_multifragment_update_capability_set when processing client-supplied DesktopWidth and DesktopHeight values during GCC negotiation and Demand Active capability writing. A remote attacker can send specially crafted desktop dimension values to cause a denial of service.
In the verified TLS-only or standard RDP security configuration without NLA, the crash occurs before credential verification. Default-build configurations with verbose assertions enabled are affected.