CVE-2026-67290

FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can send malformed media format data from a server to trigger a crash by reading fixed offsets without validating source buffer length.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-01 13:16

Updated : 2026-08-31 20:25


NVD link : CVE-2026-67290

Mitre link : CVE-2026-67290

CVE.ORG link : CVE-2026-67290


JSON object : View

Products Affected

No product.

CWE
CWE-125

Out-of-bounds Read