CVE-2026-68580

HIGH

FreeRDP before 3.29.0 Integer Overflow via Audio Input Channel

Title source: cna
STIX 2.1

Description

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can supply a malicious FramesPerPacket value causing allocation size wraparound, resulting in heap-based buffer overflow on ALSA or denial of service on all platforms.

References (2)

Core 2
Core References
Third Party Advisory third-party-advisory
VulnCheck Advisory: FreeRDP before 3.29.0 Integer Overflow via Audio Input Channel
https://www.vulncheck.com/advisories/freerdp-before-integer-overflow-via-audio-input-channel
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-69xf-pqrw-596x)
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-69xf-pqrw-596x

Scores

CVSS v3 7.5
EPSS 0.0024
EPSS Percentile 14.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-122
Status published
Products (2)
FreeRDP/FreeRDP < 3.29.0
FreeRDP/FreeRDP 3.29.0
Published Aug 02, 2026
Tracked Since Aug 02, 2026