CVE-2026-67301

FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders. When AsyncUpdate is enabled (e.g., xfreerdp /async-update), update_message_PolygonSC() and update_message_PolygonCB() allocate a fresh points array but copy point data from the address of the order structure instead of from polygonSC->points / polygonCB->points, resulting in a client-side out-of-bounds read. A malicious or compromised RDP server sending crafted PolygonSC/PolygonCB update orders can trigger memory disclosure or a client crash.
Configurations

Configuration 1 (hide)

cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-01 13:16

Updated : 2026-09-08 14:27


NVD link : CVE-2026-67301

Mitre link : CVE-2026-67301

CVE.ORG link : CVE-2026-67301


JSON object : View

Products Affected

freerdp

  • freerdp
CWE
CWE-125

Out-of-bounds Read