Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-91952

MEDIUM NVD
CVSS Score 6.5
Severity MEDIUM
Published Sep 15, 2026
Vendor unknown

Description

FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks with more region rectangles than preallocated worker array size. A malicious RDP server can send crafted AVC444 graphics updates causing the threaded decode path to loop indefinitely, consuming CPU and preventing normal client operation.

References