Loading market data...
← Back to CVE feed

CVE-2026-91961

MEDIUM CVSS 6.5 View on NVD ↗

Description

FreeRDP before 3.31.0 contains a denial-of-service vulnerability in the URBDRC control-transfer request path that fails to validate OutputBufferSize before forwarding to the libusb backend. A malicious RDP server can send a control-transfer request with OutputBufferSize set to 65536, triggering a reachable assertion that terminates the client process.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Published: Sep 15, 2026 16:17 UTC Modified: Sep 15, 2026 16:17 UTC