CVE-2026-91955

Summary

FreeRDP before 3.31.0 fails to validate client-supplied DesktopWidth and DesktopHeight values during GCC negotiation, allowing remote attackers to crash the server. Attackers can send crafted RDP packets with zero or oversized dimensions to trigger division-by-zero or assertion failures in multifragment update capability calculations, terminating the server process.

Affected Software

VendorProductVersion RangeStatus
FreeRDPFreeRDP0 < 3.31.0affected
FreeRDPFreeRDP3.31.0unaffected

Weaknesses

  • CWE-369: Divide By Zero

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: yes
    • Technical Impact: partial

Additional References

References