Divide-by-Zero Vulnerability in FreeRDP Camera Redirection Client
CVE-2026-67302
5.3MEDIUM
What is CVE-2026-67302?
FreeRDP versions prior to 3.29.0 have a vulnerability in the camera redirection client, where an attacker can exploit this flaw by sending a specially crafted StartStreamsRequest. The issue arises when the server sends a zero value for FrameRateDenominator, leading to an integer division by zero during processing. This can cause the FreeRDP client to crash, creating a denial-of-service condition. To mitigate this issue, it's essential for users to upgrade to FreeRDP version 3.29.0 or later, which addresses this vulnerability.
Affected Version(s)
FreeRDP 0 < 3.29.0
FreeRDP 3.29.0
