What is CVE-2026-67306?
A critical out-of-bounds read vulnerability exists in the planar RLE bitmap decoder of FreeRDP 3.28.0 and earlier, where only the control byte is bounds-checked, allowing an attacker to trigger DoS or potential information disclosure. Immediate update to the latest version is strongly recommended.
Azərbaycanca: Bu kritik zəiflik FreeRDP-nin 3.28.0 və əvvəlki versiyalarında RDP6 planar RLE bitmap dekoderində "out-of-bounds read" probleminə səbəb olur. Uzaqdan hücum edən şəxs planar_decompress_plane_rle funksiyasındakı nəzarət baytının düzgün yoxlanılmamasından istifadə edərək xidmət xaricə (DoS) və ya potensial məlumat sızması yarada bilər. Təhlükəsizlik üçün dərhal ən son versiyaya yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-125; shared vendor: FreeRDP
FAQ2
In which component of FreeRDP was CVE-2026-67306 discovered?
The vulnerability exists in the RDP6 planar RLE bitmap decoder of FreeRDP, specifically due to improper bounds checking of only the control byte in the planar_decompress_plane_rle function.
What impact can a remote attacker achieve by exploiting CVE-2026-67306?
An attacker can trigger a denial of service (DoS) or potentially cause information disclosure by exploiting this out-of-bounds read vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.