Out-of-Bounds Read Vulnerability in FreeRDP by FreeRDP
CVE-2026-67306

5.3MEDIUM

Key Information:

Vendor

Freerdp

Status
Vendor
CVE Published:
1 August 2026

What is CVE-2026-67306?

FreeRDP versions 3.28.0 and earlier are susceptible to an out-of-bounds read vulnerability in the planar RLE bitmap decoder functions. This issue arises from insufficient bounds-checking; while the 1-byte control byte is validated, the subsequent attacker-controlled raw bytes can lead to buffer overreads when a malicious RDP server sends an incomplete planar-encoded bitmap or surface update. The vulnerability can be exploited via Bitmap Update PDU and RDPGFX Surface Command paths, compromising client security. Users are advised to upgrade to FreeRDP 3.29.0 or later for the fix.

Affected Version(s)

FreeRDP 0 < 3.29.0

FreeRDP 3.29.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HEXER365
.