What is CVE-2026-67303?
FreeRDP versions before 3.29.0 contain a reachable assertion in the serial device redirection feature, triggered by a server-controlled IRP_MJ_DEVICE_CONTROL request. This vulnerability can lead to denial of service. Users should upgrade to version 3.29.0 or later to mitigate the issue.
Azərbaycanca: FreeRDP-nin serial cihaz yönləndirmə funksiyasında server tərəfindən göndərilən xüsusi sorğu zamanı `WINPR_ASSERT` xətası baş verir. Bu zəiflik 3.29.0-dan əvvəlki versiyalara təsir edir və xidmətin dayanmasına səbəb ola bilər. Problemi aradan qaldırmaq üçün FreeRDP-ni 3.29.0 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: FreeRDP
FAQ2
Which feature of FreeRDP is affected by CVE-2026-67303?
The vulnerability is found in the serial device redirection feature of FreeRDP.
How to mitigate the CVE-2026-67303 vulnerability?
It is recommended to upgrade FreeRDP to version 3.29.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.