Critical severity9.8NVD Advisory· Published Aug 19, 2026· Updated Sep 24, 2026
CVE-2026-63633
CVE-2026-63633
Description
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, freerdp_dsp_decode_opus in libfreerdp/codec/dsp.c calls Stream_EnsureRemainingCapacity on context->common.buffer even though opus_decode writes decoded PCM into the caller-supplied out stream. A malicious RDP server that negotiates WAVE_FORMAT_OPUS with a client built with WITH_OPUS enabled and WITH_DSP_FFMPEG disabled can make libopus write a large decoded frame beyond the 4096-byte StreamPool_Take destination used by channels/rdpsnd/client/rdpsnd_main.c. This can corrupt the client heap, crash the client, and may permit code execution. This issue is fixed in version 3.28.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8- osv-coords7 versionspkg:rpm/almalinux/libwinprpkg:rpm/almalinux/libwinpr-develpkg:rpm/almalinux/freerdp-libspkg:rpm/almalinux/freerdppkg:rpm/opensuse/freerdp&distro=openSUSE%20Tumbleweedpkg:rpm/almalinux/freerdp-develpkg:rpm/almalinux/freerdp-server
< 2:3.10.3-12.el10_2.10+ 6 more
- (no CPE)range: < 2:3.10.3-12.el10_2.10
- (no CPE)range: < 2:3.10.3-12.el10_2.10
- (no CPE)range: < 2:3.10.3-12.el10_2.10
- (no CPE)range: < 2:3.10.3-12.el10_2.10
- (no CPE)range: < 3.30.0-1.1
- (no CPE)range: < 2:3.10.3-12.el10_2.10
- (no CPE)range: < 2:3.10.3-12.el10_2.10
Patches
Vulnerability mechanics
References
4- github.com/FreeRDP/FreeRDP/commit/0ed1f95d36913581cf31124f94eb5843d4263eaenvdPatch
- github.com/FreeRDP/FreeRDP/pull/12993nvdIssue TrackingPatch
- github.com/FreeRDP/FreeRDP/security/advisories/GHSA-72j9-356v-88xqnvdExploitMitigationVendor Advisory
- github.com/FreeRDP/FreeRDP/releases/tag/3.28.0nvdRelease Notes
News mentions
1- FreeRDP: Ten Vulnerabilities Disclosed Together, Ranging from Medium to High SeverityVypr Intelligence · Aug 19, 2026