What is CVE-2026-67302?
FreeRDP versions before 3.29.0 (<=3.28.0) contain a divide-by-zero vulnerability in the rdpecam camera redirection client. The flaw exists in the 'ecam_dev_process_start_streams_request()' function when parsing a server-controlled StartStreamsRequest PDU, allowing a malicious server to trigger a crash. Users should upgrade to FreeRDP 3.29.0 or later to mitigate this issue.
Azərbaycanca: FreeRDP 3.29.0 versiyasından əvvəlki versiyalarda (<=3.28.0) rdpecam kamera yönləndirmə müştərisində 'divide-by-zero' zəifliyi aşkarlanıb. Bu zəiflik server tərəfindən idarə olunan xüsusi hazırlanmış StartStreamsRequest PDU vasitəsilə 'ecam_dev_process_start_streams_request()' funksiyasında baş verir. Təsirlənən istifadəçilər dərhal FreeRDP 3.29.0 və ya daha yeni versiyaya yeniləməlidir.
Related CVEs
link basis: shared vendor: FreeRDP
FAQ2
In which component of FreeRDP does CVE-2026-67302 occur?
This vulnerability is found in the rdpecam camera redirection client of FreeRDP.
To which version should users upgrade to mitigate CVE-2026-67302?
Users should immediately upgrade to FreeRDP 3.29.0 or a later version to mitigate this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.