Reachable assertion in FreeRDP - #VU146587
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to reachable assertion in rdp_write_multifragment_update_capability_set when processing client-supplied DesktopWidth and DesktopHeight values during GCC negotiation and Demand Active capability writing. A remote attacker can send specially crafted desktop dimension values to cause a denial of service.
In the verified TLS-only or standard RDP security configuration without NLA, the crash occurs before credential verification. Default-build configurations with verbose assertions enabled are affected.