CVE-2026-67304 Details
Description
FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails. Attackers can send malformed smartcard IRP requests with non-zero cReaders and truncated reader-state data to crash the process via null pointer access in free_reader_states functions.
A null pointer dereference vulnerability has been identified in FreeRDP versions prior to 3.29.0. This issue arises in the smartcard device control request cleanup process when decoding the reader-state data fails. Attackers can exploit this vulnerability by sending malformed smartcard IRP requests that include non-zero reader counts and truncated reader-state information. This leads to a process crash due to null pointer access in the 'free_reader_states' functions.
Users can upgrade to FreeRDP version 3.29.0 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-78jj-45vh-jpm5 | CISA-ADP | ExploitVendor Advisory |
| https://github.com/FreeRDP/FreeRDP/commit/1cc783d4c78bd2f66d3a8582dfe70a663d141444 | [email protected] | Patch |
| https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-78jj-45vh-jpm5 | [email protected] | ExploitVendor Advisory |
| https://www.vulncheck.com/advisories/freerdp-before-null-dereference-via-smartcard-cleanup | [email protected] | PatchThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| freerdp freerdp | < 3.29.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 8, 2026 | Initial Analysis | [email protected] |
| Aug 3, 2026 | CVE Modified | CISA-ADP |
| Aug 1, 2026 | New CVE Received | [email protected] |