<Vulnerability name="CVE-2026-63633">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-08-19T18:00:52</PublicDate>
    <Bugzilla id="2519826" url="https://bugzilla.redhat.com/show_bug.cgi?id=2519826" xml:lang="en:us">
freerdp: FreeRDP: Arbitrary code execution via heap buffer overflow in Opus audio decode
    </Bugzilla>
    <CVSS3 status="verified">
        <CVSS3BaseScore>8.8</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-120</CWE>
    <Details xml:lang="en:us" source="Mitre">
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, freerdp_dsp_decode_opus in libfreerdp/codec/dsp.c calls Stream_EnsureRemainingCapacity on context-&gt;common.buffer even though opus_decode writes decoded PCM into the caller-supplied out stream. A malicious RDP server that negotiates WAVE_FORMAT_OPUS with a client built with WITH_OPUS enabled and WITH_DSP_FFMPEG disabled can make libopus write a large decoded frame beyond the 4096-byte StreamPool_Take destination used by channels/rdpsnd/client/rdpsnd_main.c. This can corrupt the client heap, crash the client, and may permit code execution. This issue is fixed in version 3.28.0.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in FreeRDP, a free implementation of the Remote Desktop Protocol. A malicious Remote Desktop Protocol (RDP) server can exploit a heap buffer overflow vulnerability during Opus audio decoding. This occurs when the server negotiates Opus audio with a vulnerable client, causing the client to write data beyond an allocated memory buffer. This can lead to client crashes, memory corruption, and potentially allow the malicious server to execute arbitrary code on the client system.
    </Details>
    <Statement xml:lang="en:us">
A heap buffer overflow vulnerability was found in FreeRDP's DSP audio codec module (`libfreerdp/codec/dsp.c`). When built with `WITH_OPUS` and without `WITH_DSP_FFMPEG`, `freerdp_dsp_decode_opus` fails to validate destination buffer capacity when handling `WAVE_FORMAT_OPUS` streams. A malicious RDP server can transmit an oversized Opus frame, causing `libopus` to write beyond the 4096-byte client buffer allocated by the `rdpsnd` channel. This leads to client heap corruption, application crashes, or potential remote code execution.
    </Statement>
    <Mitigation xml:lang="en:us">
To mitigate this vulnerability, disable audio redirection on client connections by omitting audio parameters (such as `/sound` or `/audio`) in `xfreerdp` to bypass client-side DSP audio decoding.
    </Mitigation>
    <AffectedRelease cpe="cpe:/o:redhat:enterprise_linux:10.2">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <ReleaseDate>2026-08-31T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:61378">RHSA-2026:61378</Advisory>
        <Package name="freerdp">freerdp-2:3.10.3-12.el10_2.10</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:enterprise_linux_eus:10.0">
        <ProductName>Red Hat Enterprise Linux 10.0 Extended Update Support</ProductName>
        <ReleaseDate>2026-09-17T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:68706">RHSA-2026:68706</Advisory>
        <Package name="freerdp">freerdp-2:3.10.3-3.el10_0.16</Package>
    </AffectedRelease>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:6">
        <ProductName>Red Hat Enterprise Linux 6</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>freerdp</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:7">
        <ProductName>Red Hat Enterprise Linux 7</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>freerdp</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:8">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>freerdp</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>freerdp</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-63633
https://nvd.nist.gov/vuln/detail/CVE-2026-63633
https://github.com/FreeRDP/FreeRDP/commit/0ed1f95d36913581cf31124f94eb5843d4263eae
https://github.com/FreeRDP/FreeRDP/pull/12993
https://github.com/FreeRDP/FreeRDP/releases/tag/3.28.0
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-72j9-356v-88xq
    </References>
</Vulnerability>