CVE-2026-91955
FreeRDP before 3.31.0 fails to validate client-supplied DesktopWidth and DesktopHeight values during GCC negotiation, allowing remote attackers to crash the server. Attackers can send crafted RDP packets with zero or oversized dimensions to trigger division-by-zero or assertion failures in multifragment update capability calculations, terminating the server process.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.2
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.45%
- CWE
- CWE-369
- Published
- 2026-09-15
- Last modified
- 2026-09-15
Affected products
- FreeRDP FreeRDP
- FreeRDP FreeRDP
Weakness type
Related vulnerabilities
- CVE-2021-32494 — Radare2 has a division by zero vulnerability in Mach-O parser's rebase_buffer function. This allow attackers to create m
- CVE-2026-24826 — Out-of-bounds write in turso3d
- CVE-2025-4637 — Divide By Zero in dlib
- CVE-2023-3896 — A divide by zero issue existed in vim of OpenCloudOS Stream
- CVE-2024-4785 — BT: Missing Check in LL_CONNECTION_UPDATE_IND Packet Leads to Division by Zero
- CVE-2019-5637 — Beckhoff TwinCAT Profinet Driver Divide-by-Zero Denial of Service
- CVE-2024-8063 — Divide by Zero in ollama/ollama
- CVE-2025-54581 — vproxy is vulnerable to a divide by zero DoS attack