What is CVE-2026-67304?
CVE-2026-67304 is a null pointer dereference vulnerability in FreeRDP versions prior to 3.29.0, triggered during smartcard device control request cleanup when reader-state decoding fails. An attacker can crash the process by sending malformed smartcard IRP requests with non-zero cReaders and truncated reader-state data. Affected users should update to the latest version.
Azərbaycanca: CVE-2026-67304, FreeRDP-nin 3.29.0-dan əvvəlki versiyalarında smartcard cihaz nəzarət sorğularının təmizlənməsi zamanı yaranan null pointer dereference zəifliyidir. Təcavüzkar, reader-state dekodlanması uğursuz olduqda, xüsusi hazırlanmış smartcard IRP sorğuları göndərərək prosesin çökməsinə səbəb ola bilər. Təsirə məruz qalmış istifadəçilər dərhal FreeRDP-ni ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-476; shared vendor: FreeRDP
FAQ2
Which FreeRDP versions are affected by CVE-2026-67304?
This vulnerability affects FreeRDP versions prior to 3.29.0. Users should update to the latest version immediately.
What can an attacker achieve by exploiting this null pointer dereference vulnerability?
An attacker can crash the target process by sending malformed smartcard IRP requests when reader-state decoding fails.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.