Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-66401

Опубликовано: 01 авг. 2026
Источник: redhat
CVSS3: 2.1
EPSS Низкий

Описание

FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fails to validate descriptor length before accessing the GUID field. A local attacker with a malicious USB video camera can trigger a heap read beyond allocated bounds during camera stream setup, causing denial of service.

A flaw was found in FreeRDP. This out-of-bounds read vulnerability in the Universal Video Class (UVC) H.264 extension-unit parser occurs because the software fails to validate descriptor length before accessing the GUID field. A local attacker, by connecting a specially crafted malicious USB video camera, can trigger a read beyond the allocated memory bounds during camera stream setup. This can lead to a denial of service (DoS), making the application unavailable.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freerdpFix deferred
Red Hat Enterprise Linux 6freerdpOut of support scope
Red Hat Enterprise Linux 7freerdpOut of support scope
Red Hat Enterprise Linux 8freerdpFix deferred
Red Hat Enterprise Linux 9freerdpFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2510002FreeRDP: FreeRDP: Denial of Service via out-of-bounds read in UVC H.264 parser

EPSS

Процентиль: 4%
0.00149
Низкий

2.1 Low

CVSS3

Связанные уязвимости

CVSS3: 2.1
ubuntu
около 1 месяца назад

FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fails to validate descriptor length before accessing the GUID field. A local attacker with a malicious USB video camera can trigger a heap read beyond allocated bounds during camera stream setup, causing denial of service.

CVSS3: 2.1
nvd
около 1 месяца назад

FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fails to validate descriptor length before accessing the GUID field. A local attacker with a malicious USB video camera can trigger a heap read beyond allocated bounds during camera stream setup, causing denial of service.

CVSS3: 2.1
debian
около 1 месяца назад

FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerabilit ...

CVSS3: 2.1
github
около 1 месяца назад

FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fails to validate descriptor length before accessing the GUID field. A local attacker with a malicious USB video camera can trigger a heap read beyond allocated bounds during camera stream setup, causing denial of service.

EPSS

Процентиль: 4%
0.00149
Низкий

2.1 Low

CVSS3