Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-67304

Опубликовано: 01 авг. 2026
Источник: redhat
CVSS3: 6.5

Описание

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails. Attackers can send malformed smartcard IRP requests with non-zero cReaders and truncated reader-state data to crash the process via null pointer access in free_reader_states functions.

A null pointer dereference flaw in FreeRDP allows a remote attacker to cause a denial of service (DoS) via specially crafted smartcard requests. If reader-state decoding fails, the system attempts to free uninitialized states during cleanup, resulting in a process crash.

Отчет

This Moderate-impact vulnerability causes a denial of service (DoS) in FreeRDP clients and proxies. If smartcard redirection is enabled, an attacker (via a malicious server or proxy client) can send specially crafted smartcard IRP requests to trigger a null pointer dereference during cleanup. Note: FreeRDP packages shipped in Red Hat Enterprise Linux (RHEL) 9 and older are not affected.

Меры по смягчению последствий

To mitigate this issue, disable smartcard redirection in FreeRDP client configurations if smartcard functionality is not required. This can typically be achieved by launching the xfreerdp client without the /smartcard option, or by explicitly setting /smartcard:no if a configuration file is used. Disabling smartcard redirection will prevent the use of smartcard devices with FreeRDP sessions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freerdpAffected
Red Hat Enterprise Linux 6freerdpNot affected
Red Hat Enterprise Linux 7freerdpNot affected
Red Hat Enterprise Linux 8freerdpNot affected
Red Hat Enterprise Linux 9freerdpNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2510034FreeRDP: FreeRDP: Denial of Service via null pointer dereference in smartcard cleanup

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails. Attackers can send malformed smartcard IRP requests with non-zero cReaders and truncated reader-state data to crash the process via null pointer access in free_reader_states functions.

CVSS3: 7.5
nvd
около 1 месяца назад

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails. Attackers can send malformed smartcard IRP requests with non-zero cReaders and truncated reader-state data to crash the process via null pointer access in free_reader_states functions.

CVSS3: 7.5
debian
около 1 месяца назад

FreeRDP before 3.29.0 contains a null pointer dereference vulnerabilit ...

CVSS3: 7.5
github
около 1 месяца назад

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails. Attackers can send malformed smartcard IRP requests with non-zero cReaders and truncated reader-state data to crash the process via null pointer access in free_reader_states functions.

CVSS3: 7.5
fstec
около 2 месяцев назад

Уязвимость функций free_reader_states_a() и free_reader_states_w() RDP-клиента FreeRDP, позволяющая нарушителю вызвать отказ в обслуживании

6.5 Medium

CVSS3