PT-2026-67268 · Freerdp · Freerdp

·

CVE-2026-67288

·

Published

2026-08-01

·

Updated

2026-08-01

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.29.0
Description A null pointer dereference occurs in smartcard cache request decoders when they accept NULL NDR pointers for LookupName during SCARD IOCTL READCACHEA and SCARD IOCTL WRITECACHEA operations. If smartcard emulation is enabled, an attacker can send crafted smartcard cache requests with NULL lookup-name pointers to trigger the strlen() function on a null pointer, leading to the termination of the client process.
Recommendations Update to version 3.29.0 or later. Disable smartcard emulation to mitigate the risk of exploitation.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67288
GHSA-PH3Q-F9W8-7JF3

Affected Products

Freerdp