Out-of-Bounds Heap Read Vulnerability in FreeRDP by FreeRDP
CVE-2026-66401

2.4LOW

Key Information:

Vendor

Freerdp

Status
Vendor
CVE Published:
1 August 2026

What is CVE-2026-66401?

FreeRDP, prior to version 3.29.0, is susceptible to an out-of-bounds heap read due to a flaw in the UVC H.264 extension-unit parser. The vulnerability arises when the system does not properly validate the descriptor length before accessing the GUID field. This oversight allows a local attacker to exploit the issue with a malicious USB video camera during the camera stream setup, potentially leading to a denial of service.

Affected Version(s)

FreeRDP 0 < 3.29.0

FreeRDP 3.29.0

References

CVSS V4

Score:
2.4
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

acorn421
.