CVE-2026-91952
MEDIUM
NVD
CVSS Score
6.5
Severity
MEDIUM
Published
Sep 15, 2026
Vendor
unknown
Description
FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks with more region rectangles than preallocated worker array size. A malicious RDP server can send crafted AVC444 graphics updates causing the threaded decode path to loop indefinitely, consuming CPU and preventing normal client operation.