CVE-2026-68580
Received Received - Intake

Integer Overflow in FreeRDP Audio Input Redirection

Vulnerability report for CVE-2026-68580, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-02

Last updated on: 2026-08-02

Assigner: VulnCheck

Description

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can supply a malicious FramesPerPacket value causing allocation size wraparound, resulting in heap-based buffer overflow on ALSA or denial of service on all platforms.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-02
Last Modified
2026-08-02
Generated
2026-08-02
AI Q&A
2026-08-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
freerdp freerdp to 3.29.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-122 A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

FreeRDP before version 3.29.0 has an integer overflow flaw in the audio input redirection channel (audin) across multiple audio backends including ALSA, sndio, WinMM, and OpenSL ES. The issue occurs when the FramesPerPacket parameter from RDP servers is not properly validated, leading to allocation size wraparound and subsequent heap-based buffer overflow or denial of service.

Impact Analysis

This vulnerability could allow attackers to execute arbitrary code, crash applications, or cause denial of service by sending specially crafted audio input data through an RDP connection. Users relying on FreeRDP for remote desktop sessions may experience system instability or potential unauthorized access if the software is not updated.

Mitigation Strategies

Update FreeRDP to version 3.29.0 or later to address the integer overflow vulnerabilities in the audio input redirection channel.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-68580. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart