PT-2026-57294 · Freerdp+2 · Freerdp+2

CVE-2026-57157

·

Published

2026-07-10

·

Updated

2026-08-10

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.28.0
Description FreeRDP server implementations with the MS-RDPECAM camera device enumerator channel enabled contain a flaw where the system scans the DeviceName and VirtualChannelName fields for a NUL terminator in the channels/rdpecam/server/camera device enumerator main.c file. The system then dereferences once past the scan bound, which allows a malicious RDP client to trigger a 1- to 2-byte out-of-bounds heap read. An out-of-bounds heap read occurs when a program reads data past the end of the allocated memory buffer on the heap.
Recommendations Update to version 3.28.0. As a temporary mitigation, disable the MS-RDPECAM camera device enumerator channel.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57157
GHSA-47FR-JW86-C3FJ
OPENSUSE-SU-2026:11263-1
SUSE-SU-2026:3562-1
USN-8561-1

Affected Products

Freerdp
Linuxmint
Ubuntu