Description

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, the function `Stream_EnsureCapacity` can create an endless blocking loop. This may affect all client and server implementations using `FreeRDP`. For practical exploitation this will only work on 32bit systems where the available physical memory is `>= SIZE_MAX`. Version 3.23.0 contains a patch. No known workarounds are available.

INFO

Published Date :

2026-02-25T21:07:30.828Z

Last Modified :

2026-02-25T21:43:56.822Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-27951 vulnerability.

Vendors Products
Freerdp
  • Freerdp

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact