Security Advisory

CVE-2026-91962

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-15 15:18:15
Last updated 2026-09-15 15:18:15
Assigner VulnCheck
CVSS score 6.3
State PUBLISHED

Description

FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values from MSG_SNDIN_OPEN messages. Attackers can supply crafted FramesPerPacket values that cause AudioQueueAllocateBuffer size computation to wrap, resulting in undersized buffer allocation and potential out-of-bounds access.