Reachable assertion in FreeRDP - #VU152392
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a reachable assertion in the urb_isoch_transfer IN transfer path when processing a malicious RDP server's USB redirection request with an oversized OutputBufferSize value. A remote attacker can send a crafted TS_URB_ISOCH_TRANSFER request to cause a denial of service.
Exploitation requires the USB redirection channel (URBDRC) and no user interaction beyond connecting to the server.