CVE-2026-68580
HIGHFreeRDP before 3.29.0 Integer Overflow via Audio Input Channel
Title source: cnaDescription
FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can supply a malicious FramesPerPacket value causing allocation size wraparound, resulting in heap-based buffer overflow on ALSA or denial of service on all platforms.
References (2)
Core 2
Core References
Third Party Advisory third-party-advisory
VulnCheck Advisory: FreeRDP before 3.29.0 Integer Overflow via Audio Input Channel
https://www.vulncheck.com/advisories/freerdp-before-integer-overflow-via-audio-input-channel
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-69xf-pqrw-596x)
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-69xf-pqrw-596x
Scores
CVSS v3
7.5
EPSS
0.0024
EPSS Percentile
14.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-122
Status
published
Products (2)
FreeRDP/FreeRDP
< 3.29.0
FreeRDP/FreeRDP
3.29.0
Published
Aug 02, 2026
Tracked Since
Aug 02, 2026