Heap Buffer Overflow in FreeRDP Server-Side RAIL Channel Handler
CVE-2026-67298
8.7HIGH
What is CVE-2026-67298?
FreeRDP versions 3.28.0 and earlier are susceptible to a heap buffer overflow vulnerability in the server-side RAIL channel handler. The issue arises when processing a RAIL PDU header, where the orderLength field is not adequately verified against its expected minimum. This oversight allows an attacker to exploit the vulnerability by providing a small orderLength value, leading to an unsigned integer underflow. Consequently, this can bypass critical checks and result in an out-of-bounds heap write, potentially crashing the server and compromising system integrity. It is recommended that users upgrade to FreeRDP version 3.29.0 or later to mitigate this risk.
Affected Version(s)
FreeRDP 0 < 3.29.0
FreeRDP 3.29.0
