High severity7.5NVD Advisory· Published Aug 2, 2026· Updated Aug 31, 2026
CVE-2026-68580
CVE-2026-68580
Description
FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can supply a malicious FramesPerPacket value causing allocation size wraparound, resulting in heap-based buffer overflow on ALSA or denial of service on all platforms.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- osv-coords6 versionspkg:rpm/almalinux/freerdp-develpkg:rpm/almalinux/freerdp-libspkg:rpm/almalinux/freerdp-serverpkg:rpm/almalinux/libwinpr-develpkg:rpm/almalinux/libwinprpkg:rpm/almalinux/freerdp
< 2:2.11.7-11.el8_10+ 5 more
- (no CPE)range: < 2:2.11.7-11.el8_10
- (no CPE)range: < 2:2.11.7-11.el8_10
- (no CPE)range: < 2:3.10.3-12.el10_2.8
- (no CPE)range: < 2:2.11.7-11.el8_10
- (no CPE)range: < 2:2.11.7-11.el8_10
- (no CPE)range: < 2:2.11.7-11.el8_10
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.