Denial of Service Vulnerability in FreeRDP by FreeRDP
CVE-2026-67303

5.3MEDIUM

Key Information:

Vendor

Freerdp

Status
Vendor
CVE Published:
1 August 2026

What is CVE-2026-67303?

FreeRDP, prior to version 3.29.0, is affected by a denial of service vulnerability caused by a reachable assertion in the serial device redirection component. When a server-controlled IOCTL request, which specifies a non-zero OutputBufferLength, is sent, it can lead to a failure in CommDeviceIoControl(). This results in BytesReturned being zero, triggering an assertion failure that causes the client process to abort.

Affected Version(s)

FreeRDP 0 < 3.29.0

FreeRDP 3.29.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

1121984919
.