Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FreeRDP versions before 3.31.0 contain an out-of-bounds read vulnerability in smartcard response decoders that fail to validate ATR length fields against fixed inline arrays. Authenticated RDP clients can send oversized ATR lengths in PAKID_CORE_DEVICE_IOCOMPLETION responses to trigger reads past stack or heap objects, causing process termination. | |
| Title | FreeRDP before 3.31.0 Out-of-bounds Read via Smartcard ATR | |
| First Time appeared |
Freerdp
Freerdp freerdp |
|
| Weaknesses | CWE-125 | |
| CPEs | cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Freerdp
Freerdp freerdp |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T15:52:09.501Z
Reserved: 2026-09-15T11:07:01.913Z
Link: CVE-2026-91945
Updated: 2026-09-15T15:52:05.990Z
Status : Received
Published: 2026-09-15T16:17:46.657
Modified: 2026-09-15T16:17:46.657
Link: CVE-2026-91945
No data.
OpenCVE Enrichment
Updated: 2026-09-15T17:30:10Z