PT-2026-67271 · Freerdp · Freerdp

·

CVE-2026-67291

·

Published

2026-08-01

·

Updated

2026-08-01

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.29.0
Description A heap out-of-bounds read exists in the update process glyph fragments() and glyph cache fragment put() functions within libfreerdp/cache/glyph.c. The issue occurs during the handling of a GLYPH FRAGMENT ADD update, where the system reads a one-byte server-controlled declared fragment size without verifying if it fits within the remaining received buffer before allocation and copying. A malicious RDP server can trigger this by sending a short fragment with an oversized declared size, causing the client to read beyond the allocated buffer and crash.
Recommendations Update to version 3.29.0 or later.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67291
GHSA-HGJ8-G595-WFC6

Affected Products

Freerdp