Out-of-Bounds Read Vulnerability in FreeRDP by FreeRDP
CVE-2026-67306
5.3MEDIUM
What is CVE-2026-67306?
FreeRDP versions 3.28.0 and earlier are susceptible to an out-of-bounds read vulnerability in the planar RLE bitmap decoder functions. This issue arises from insufficient bounds-checking; while the 1-byte control byte is validated, the subsequent attacker-controlled raw bytes can lead to buffer overreads when a malicious RDP server sends an incomplete planar-encoded bitmap or surface update. The vulnerability can be exploited via Bitmap Update PDU and RDPGFX Surface Command paths, compromising client security. Users are advised to upgrade to FreeRDP 3.29.0 or later for the fix.
Affected Version(s)
FreeRDP 0 < 3.29.0
FreeRDP 3.29.0
