Out-of-bounds read in FreeRDP - CVE-2026-67292

 

Out-of-bounds read in FreeRDP - CVE-2026-67292

Published: July 16, 2026 / Updated: September 14, 2026


Vulnerability identifier: #VU137829
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-67292
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an over-read caused by improper stream length handling in the gateway WebSocket transport when processing server-sent ping control frames. A remote attacker can send a specially crafted ping frame to disclose sensitive information.

The client sends a Pong whose payload may include bytes beyond the received Ping payload, and the peer can recover the masked payload because it receives the WebSocket masking key.


Affected software

FreeRDP

How to mitigate CVE-2026-67292

Install security update from vendor's website.

FreeRDP - update to 3.29.0

External References

Related Security Bulletins