Reachable assertion in FreeRDP - #VU146596
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to reachable assertion in URBDRC/libusb control-transfer path when processing a server-supplied URBDRC control-transfer request. A remote attacker can send a crafted request with an oversized OutputBufferSize value to cause a denial of service.
The issue is triggered when OutputBufferSize is set to 65536, and exploitation affects builds that use the URBDRC libusb path after the user connects to a malicious server.