CVE-2026-67288

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emulation is enabled, attackers can send crafted smartcard cache requests with NULL lookup-name pointers to trigger strlen() on a null pointer, causing client process termination.
Configurations

Configuration 1 (hide)

cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-01 13:16

Updated : 2026-09-03 19:38


NVD link : CVE-2026-67288

Mitre link : CVE-2026-67288

CVE.ORG link : CVE-2026-67288


JSON object : View

Products Affected

freerdp

  • freerdp
CWE
CWE-476

NULL Pointer Dereference