---
id: CVE-2026-68580
title: >-
  FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio
  input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES
  backends that fail to validate the FramesPerPacket parameter from RDP servers
summary: >-
  FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio
  input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES
  backends that fail to validate the FramesPerPacket parameter from RDP servers.
  Attack…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-122
published: '2026-08-02'
updated: '2026-08-02'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-68580'
references:
  - url: 'https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-69xf-pqrw-596x'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/freerdp-before-integer-overflow-via-audio-input-channel
    label: disclosure@vulncheck.com
tags:
  - nvd
ingestedAt: '2026-08-02T13:18:30.063Z'
epss: 0.00401
epssPercentile: 0.31537
---

## Overview

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can supply a malicious FramesPerPacket value causing allocation size wraparound, resulting in heap-based buffer overflow on ALSA or denial of service on all platforms.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
