Security Advisory

CVE-2026-91952

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-15 15:18:09
Last updated 2026-09-15 15:18:09
Assigner VulnCheck
CVSS score 7.1
State PUBLISHED

Description

FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks with more region rectangles than preallocated worker array size. A malicious RDP server can send crafted AVC444 graphics updates causing the threaded decode path to loop indefinitely, consuming CPU and preventing normal client operation.