Null Pointer Dereference in FreeRDP Affects Smartcard Emulation
CVE-2026-67288
8.7HIGH
What is CVE-2026-67288?
FreeRDP versions prior to 3.29.0 are vulnerable to a null pointer dereference issue in the smartcard cache request decoders. When smartcard emulation is activated, malicious actors can exploit this vulnerability by sending carefully crafted requests with NULL lookup-name pointers to the SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. This can lead to the termination of the client process when the system attempts to evaluate the length of a null pointer, resulting in a denial of service.
Affected Version(s)
FreeRDP 0 < 3.29.0
FreeRDP 3.29.0
