Out-of-bounds read in FreeRDP - #VU146588
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in func_get_ep_desc() in the URBDRC channel when processing a crafted SELECT_CONFIGURATION descriptor followed by a bulk or interrupt transfer request. A remote attacker can send a crafted RDP server response to cause a denial of service.
Exploitation is reachable on clients with USB redirection enabled and relies on an InterfaceNumber-to-array-position mismatch together with an unchecked AlternateSetting index.