Divide-by-Zero Vulnerability in FreeRDP Camera Redirection Client
CVE-2026-67302

5.3MEDIUM

Key Information:

Vendor

Freerdp

Status
Vendor
CVE Published:
1 August 2026

What is CVE-2026-67302?

FreeRDP versions prior to 3.29.0 have a vulnerability in the camera redirection client, where an attacker can exploit this flaw by sending a specially crafted StartStreamsRequest. The issue arises when the server sends a zero value for FrameRateDenominator, leading to an integer division by zero during processing. This can cause the FreeRDP client to crash, creating a denial-of-service condition. To mitigate this issue, it's essential for users to upgrade to FreeRDP version 3.29.0 or later, which addresses this vulnerability.

Affected Version(s)

FreeRDP 0 < 3.29.0

FreeRDP 3.29.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.