CVE-2026-68580: FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to valida
FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can supply a malicious FramesPerPacket value causing allocation size wraparound, resulting in heap-based buffer overflow on ALSA or denial of service on all platforms.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-68580
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-68580 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for FreeRDP
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalCVE-2026-68579: FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboa…nvd · 2026-08-02
- mediumCVE-2026-67306: FreeRDP versions 3.28.0 and earlier contain an out-of-bounds read vulnerability in the RDP6 pl…nvd · 2026-08-01
- unknownCVE-2026-67305: FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clip…nvd · 2026-08-01
- highCVE-2026-67304: FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device co…nvd · 2026-08-01
- mediumCVE-2026-67303: FreeRDP before 3.29.0 contains a reachable assertion (WINPR_ASSERT(OutputBufferLength == Bytes…nvd · 2026-08-01
- mediumCVE-2026-67302: FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a divide-by-zero vulnerability in…nvd · 2026-08-01
More from NVD Recent CVEs
- mediumCVE-2026-68583: luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in t…2026-08-02
- mediumCVE-2026-68582: Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vul…2026-08-02
- highCVE-2026-68581: Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token managem…2026-08-02
- criticalCVE-2026-68579: FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboa…2026-08-02
- highCVE-2026-68578: ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP trans…2026-08-02