CVE-2026-67304

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails. Attackers can send malformed smartcard IRP requests with non-zero cReaders and truncated reader-state data to crash the process via null pointer access in free_reader_states functions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-01 13:16

Updated : 2026-09-08 14:07


NVD link : CVE-2026-67304

Mitre link : CVE-2026-67304

CVE.ORG link : CVE-2026-67304


JSON object : View

Products Affected

freerdp

  • freerdp
CWE
CWE-476

NULL Pointer Dereference