Out-of-bounds read in FreeRDP - #VU152796
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in the smartcard_LocateCardsByATRA_Call handler when processing crafted LocateCardsByATRA messages. A remote user can send crafted LocateCardsByATRA messages to disclose sensitive information.
Exploitation requires smartcard-related features to be enabled.