Integer overflow in FreeRDP - #VU146595
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow or wraparound in Stream_EnsureCapacity and Stream_EnsureRemainingCapacity when processing a crafted WebSocket frame length from an RD Gateway peer. A remote attacker can send a specially crafted WebSocket Ping frame to cause a denial of service.
User interaction is required because the victim must be induced to connect through the attacker\'s RD Gateway, such as via a supplied .rdp file.