Out-of-bounds read in FreeRDP - #VU146576
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to out-of-bounds read in smartcard response decoders in libfreerdp/utils/smartcard_pack.c when processing smartcard device-I/O completion responses with oversized ATR lengths. A remote user can send a structurally valid smartcard response with an oversized ATR length to cause a denial of service.
The server must enable smartcard redirection and have an outstanding Status or GetStatusChange request.