Null Pointer Dereference in FreeRDP Smartcard Device Control
CVE-2026-67304
8.7HIGH
What is CVE-2026-67304?
A vulnerability exists in FreeRDP prior to version 3.29.0 due to inadequate handling of smartcard device control requests. Specifically, when the cleanup process encounters a faulty reader-state decoding, it can lead to a null pointer dereference. This issue arises when an attacker sends malformed IRP requests with non-zero cReaders alongside truncated reader-state data. Such actions can cause the application to crash, potentially leading to service disruptions.
Affected Version(s)
FreeRDP 0 < 3.29.0
FreeRDP 3.29.0
