What is CVE-2026-67290?
A heap out-of-bounds read vulnerability (CVE-2026-67290) exists in FreeRDP versions before 3.29.0, specifically in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData validation. A remote attacker can send malformed media format data from a server to trigger a crash on the client. Affected users should update to FreeRDP version 3.29.0 or later to apply the security patch.
Azərbaycanca: FreeRDP-in 3.29.0-dən əvvəlki versiyalarında TSMF FFmpeg dekoderində heap out-of-bounds read zəifliyi (CVE-2026-67290) aşkar edilib. Bu, AVC1 MPEG2VIDEOINFO media növünün ExtraData sahəsinin düzgün yoxlanılmaması səbəbindən baş verir və uzaqdan hücum edən şəxs server vasitəsilə xüsusi hazırlanmış məlumat göndərərək müştəri proqramında çökməyə səbəb ola bilər. Təsirlənmiş istifadəçilər təhlükəsizlik yaması üçün FreeRDP-i 3.29.0 və ya daha yeni versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-125; shared vendor: FreeRDP
FAQ2
Which versions of FreeRDP are affected by CVE-2026-67290?
FreeRDP versions before 3.29.0 are affected by this vulnerability.
How to protect against CVE-2026-67290?
Users should update to FreeRDP version 3.29.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.