CVE-2026-57157: Out-of-bounds read in the camera device enumerator server (rdpecam) via unterminated DeviceName / VirtualChannelName
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, FreeRDP server implementations with the MS-RDPECAM camera device enumerator channel enabled scan attacker-supplied DeviceName and VirtualChannelName fields for a NUL terminator in channels/rdpecam/server/cameradeviceenumeratormain.c and then dereference once past the scan bound, allowing a malicious RDP client to trigger a 1- to 2-byte out-of-bounds heap read. This issue is fixed in version 3.28.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
freerdpto a version that resolves this vulnerability.Fixed in 3.28.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57157?
The severity of CVE-2026-57157 is rated as medium with a score of 6.5.
How do I fix CVE-2026-57157?
To fix CVE-2026-57157, update to FreeRDP version 3.28.0 or later.
What causes CVE-2026-57157?
CVE-2026-57157 is caused by an out-of-bounds read in the camera device enumerator server due to unterminated DeviceName and VirtualChannelName fields.
Which software is affected by CVE-2026-57157?
CVE-2026-57157 affects FreeRDP server implementations with the MS-RDPECAM camera device enumerator channel enabled.
What are the potential impacts of CVE-2026-57157?
The potential impacts of CVE-2026-57157 include information leaks due to the out-of-bounds read.