PT-2026-67282 · Freerdp · Freerdp

CVE-2026-67302

·

Published

2026-08-01

·

Updated

2026-08-01

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.29.0
Description The rdpecam camera redirection client contains a divide-by-zero issue. The function ecam dev process start streams request() parses a server-controlled CAM MEDIA TYPE DESCRIPTION from a StartStreamsRequest PDU but fails to validate the FrameRateDenominator variable. If a compromised RDP server sends a StartStreamsRequest where FrameRateDenominator is set to zero, the function ecam encoder context init() attempts to divide FrameRateNumerator by FrameRateDenominator, resulting in a SIGFPE (signal floating-point exception) and the termination of the client process. This issue is only reachable if camera redirection is enabled on the client.
Recommendations Update to version 3.29.0. Disable camera redirection on the client to prevent the channel from being reachable.

Exploit

Fix

Divide By Zero

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67302
GHSA-V89X-PC32-HQR7

Affected Products

Freerdp