Freerdp · Freerdp · CVE-2026-68580
**Name of the Vulnerable Software and Affected Versions**
FreeRDP versions prior to 3.29.0
**Description**
Integer overflow issues exist in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends. The software fails to validate the `FramesPerPacket` parameter received from RDP servers. A malicious value for `FramesPerPacket` can cause an allocation size wraparound, leading to a heap-based buffer overflow on ALSA or a denial of service across all supported platforms.
**Recommendations**
Update to version 3.29.0 or later.