CVE-2026-66401: FreeRDP before 3.29.0 Out-of-Bounds Read via UVC H.264
FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fails to validate descriptor length before accessing the GUID field. A local attacker with a malicious USB video camera can trigger a heap read beyond allocated bounds during camera stream setup, causing denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66401?
CVE-2026-66401 has a severity rating of low at 2.1.
How does CVE-2026-66401 impact FreeRDP users?
CVE-2026-66401 allows a local attacker to trigger an out-of-bounds heap read via the UVC H.264 extension-unit parser.
What version of FreeRDP is affected by CVE-2026-66401?
FreeRDP versions before 3.29.0 are impacted by CVE-2026-66401.
How can I protect against CVE-2026-66401?
To protect against CVE-2026-66401, upgrade to FreeRDP version 3.29.0 or later.
What type of attack does CVE-2026-66401 involve?
CVE-2026-66401 involves a local attack using a malicious USB video camera to exploit the out-of-bounds read.