PT-2026-67284 · Freerdp · Freerdp

CVE-2026-67304

·

Published

2026-07-15

·

Updated

2026-08-31

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.29.0
Description A null pointer dereference occurs during the cleanup of smartcard device control requests when reader-state decoding fails. An attacker can trigger a process crash by sending malformed smartcard IRP (I/O Request Packet) requests containing non-zero cReaders and truncated reader-state data, leading to null pointer access within the free reader states() function.
Recommendations Update to version 3.29.0 or later.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:61378
BDU:2026-10990
CVE-2026-67304
GHSA-78JJ-45VH-JPM5

Affected Products

Freerdp