HIGHVulnerability

CVE-2026-68580

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can supply a malicious FramesPerPacket value causing allocation size wraparound, resulting in heap-based buffer overflow on ALSA or denial of service on all platforms.

Properties

severity
HIGH
score
7.5
cve_id
CVE-2026-68580
vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
published_at
2026-08-02T13:16:53.950
last_modified
2026-08-05T14:17:10.217

Related Entities (2)

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Heap-based Buffer Overflow

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-68580 — Ninja Signal Threat Intelligence | Ninja Signal