Back to search

CVE-2026-68580

HIGH
7.5NVD

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can supply a malicious FramesPerPacket value causing allocation size wraparound, resulting in heap-based buffer overflow on ALSA or denial of service on all platforms.

Share:

CVSS v3.1 Score

7.5
/ 10.0
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Information

Published
2 août 2026
Updated
2 août 2026
Status
Received
Source
disclosure@vulncheck.com

Weaknesses (CWE)

CWE-122

Similar CVEs

Other vulnerabilities of type CWE-122

Loading…

Monitor your products

Get automatic alerts for every new CVE affecting your equipment.

Enable monitoring