CVE-2026-91962
FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values from MSG_SNDIN_OPEN messages. Attackers can supply crafted FramesPerPacket values that cause AudioQueueAllocateBuffer size computation to wrap, resulting in undersized buffer allocation and potential out-of-bounds access.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
- EPSS probability
- 0.24%
- CWE
- CWE-131
- Published
- 2026-09-15
- Last modified
- 2026-09-15
Affected products
- FreeRDP FreeRDP
- FreeRDP FreeRDP
Weakness type
Related vulnerabilities
- CVE-2023-36824 — Heap overflow in COMMAND GETKEYS and ACL evaluation in Redis
- CVE-2024-23622 — IBM Merge Healthcare eFilm Workstation License Server CopySLS_Request3 Buffer Overflow
- CVE-2024-23621 — IBM Merge Healthcare eFilm Workstation License Server Buffer Overflow
- CVE-2021-0254 — Junos OS: Remote code execution vulnerability in overlayd service
- CVE-2020-13585 — An out-of-bounds write vulnerability exists in the PSD Header processing functionality of Accusoft ImageGear 19.8. A spe
- CVE-2023-24819 — RIOT-OS vulnerable to Buffer Overflow during IPHC receive
- CVE-2022-22137 — A memory corruption vulnerability exists in the ioca_mys_rgb_allocate functionality of Accusoft ImageGear 19.10. A speci
- CVE-2021-21793 — An out-of-bounds write vulnerability exists in the JPG sof_nb_comp header processing functionality of Accusoft ImageGear