Integer overflow in FreeRDP - #VU146597
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service and potentially corrupt memory.
The vulnerability exists due to integer overflow or wraparound in the audin Apple backends when processing server-controlled audio format values during audin negotiation. A remote attacker can send a crafted MSG_SNDIN_OPEN message with a malicious FramesPerPacket value to cause a denial of service and potentially corrupt memory.
The issue affects the macOS and iOS audin backends, and on macOS the wrapped allocation size can become 4 bytes while AudioQueueAllocateBuffer() still succeeds.