CVE-2026-67290: FreeRDP before 3.29.0 Heap Out-of-Bounds Read via TSMF
FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can send malformed media format data from a server to trigger a crash by reading fixed offsets without validating source buffer length.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FreeRDPto a version that resolves this vulnerability.Fixed in 3.29.0 - Compensating control
If you use FreeRDP TSMF, restrict incoming media/font/TSMF-related processing to trusted servers/sessions to reduce exposure to malformed media data that could trigger the heap out-of-bounds read.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-67290?
CVE-2026-67290 has a severity rating of 8.7, indicating a high risk.
How do I fix CVE-2026-67290?
To mitigate CVE-2026-67290, upgrade FreeRDP to version 3.29.0 or later, which includes the necessary patches.
What causes CVE-2026-67290?
CVE-2026-67290 is caused by a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder in FreeRDP before version 3.29.0.
Who is affected by CVE-2026-67290?
Any users of FreeRDP versions prior to 3.29.0 are at risk from CVE-2026-67290.
What type of vulnerability is CVE-2026-67290?
CVE-2026-67290 is classified as a heap out-of-bounds read vulnerability.