What is CVE-2026-67298?
A heap buffer overflow vulnerability exists in the server-side RAIL channel of FreeRDP versions 3.28.0 and earlier. This flaw could lead to remote code execution. Users should immediately upgrade to a version newer than 3.28.0.
Azərbaycanca: FreeRDP server tərəfində RAIL kanalında heap buffer overflow zəifliyi aşkarlanıb. Bu zəiflik uzaqdan kod icrasına səbəb ola bilər. FreeRDP istifadəçiləri dərhal 3.28.0-dan yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-122; shared vendor: FreeRDP
FAQ2
Which component of FreeRDP is affected by vulnerability CVE-2026-67298?
The vulnerability exists in the server-side RAIL channel of FreeRDP.
What is the recommended solution for CVE-2026-67298?
Users should immediately upgrade to a FreeRDP version newer than 3.28.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.