Denial of Service Vulnerability in FreeRDP by FreeRDP
CVE-2026-67303
5.3MEDIUM
What is CVE-2026-67303?
FreeRDP, prior to version 3.29.0, is affected by a denial of service vulnerability caused by a reachable assertion in the serial device redirection component. When a server-controlled IOCTL request, which specifies a non-zero OutputBufferLength, is sent, it can lead to a failure in CommDeviceIoControl(). This results in BytesReturned being zero, triggering an assertion failure that causes the client process to abort.
Affected Version(s)
FreeRDP 0 < 3.29.0
FreeRDP 3.29.0
