PT-2026-67284 · Freerdp · Freerdp
CVE-2026-67304
·
Published
2026-07-15
·
Updated
2026-08-31
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
FreeRDP versions prior to 3.29.0
Description
A null pointer dereference occurs during the cleanup of smartcard device control requests when reader-state decoding fails. An attacker can trigger a process crash by sending malformed smartcard IRP (I/O Request Packet) requests containing non-zero
cReaders and truncated reader-state data, leading to null pointer access within the free reader states() function.Recommendations
Update to version 3.29.0 or later.
Exploit
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freerdp