What is CVE-2026-67291?
A heap out-of-bounds read vulnerability exists in FreeRDP versions before 3.29.0, specifically in the update_process_glyph_fragments() function due to improper validation of a server-controlled fragment size. Users should immediately update to version 3.29.0 or later to mitigate the risk.
Azərbaycanca: FreeRDP-nin 3.29.0 versiyasından əvvəlki versiyalarında heap-based out-of-bounds read zəifliyi aşkar edilib. Bu zəiflik update_process_glyph_fragments() funksiyasında serverin idarə etdiyi fragment ölçüsünün düzgün yoxlanılmaması səbəbindən baş verir. İstifadəçilər dərhal 3.29.0 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-125; shared vendor: FreeRDP
FAQ2
Why is CVE-2026-67291 in FreeRDP a security risk?
It is a heap-based out-of-bounds read vulnerability in the update_process_glyph_fragments() function caused by improper validation of a server-controlled fragment size. This flaw could potentially allow reading of memory data.
How to protect against CVE-2026-67291?
Users should immediately update FreeRDP to version 3.29.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.