CVE-2026-67296: FreeRDP before 3.29.0 Denial of Service via RDPEI PDU
Published Aug 1, 2026
·Updated
FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large declared body length to force excessive memory allocation on the server.
Affected Software
1 affected component
FreeRDP freerdp<3.29.0
Event History
Aug 1, 2026
CVE Published
via MITRE·12:22 PM
Data Sourced
via MITRE·12:22 PM
DescriptionSeverityWeakness
Data Sourced
via Red Hat·01:04 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-67296?
The severity of CVE-2026-67296 is rated high with a score of 8.7.
2
How do I fix CVE-2026-67296?
To fix CVE-2026-67296, update FreeRDP to version 3.29.0 or later.
3
What type of attack does CVE-2026-67296 facilitate?
CVE-2026-67296 facilitates a Denial of Service (DoS) attack via the RDPEI server channel.
4
What versions of FreeRDP are affected by CVE-2026-67296?
FreeRDP versions before 3.29.0 are affected by CVE-2026-67296.
5
What can an attacker do with CVE-2026-67296?
An attacker can send a malicious RDP message that can cause excessive memory allocation, leading to a Denial of Service.