HIGHVulnerability
Verified
Global
NVD HIGH: CVE-2026-67296 — FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI se...
·Source: NIST NVD
Updated:
Executive Summary
FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large declared body length to force excessive memory allocation on the server.
Analysis
FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large declared body length to force excessive memory allocation on the server. CVSS Score: 7.5. Published: 2026-08-01T13:16:58.830.