CVE-2026-67303: FreeRDP before 3.29.0 Denial of Service via serial DeviceControl
FreeRDP before 3.29.0 contains a reachable assertion (WINPRASSERT(OutputBufferLength == BytesReturned)) in serialprocessirpdevicecontrol() in channels/serial/client/serialmain.c. When serial device redirection is enabled and a server-controlled IRPMJDEVICECONTROL request specifies an unsupported IOCTL with a non-zero OutputBufferLength, CommDeviceIoControl() can fail with BytesReturned = 0, causing the mismatch to trigger the assertion and abort the client process (denial of service).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FreeRDPto a version that resolves this vulnerability.Fixed in 3.29.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-67303?
The severity of CVE-2026-67303 is medium with a CVSS score of 4.3.
How do I fix CVE-2026-67303?
To fix CVE-2026-67303, update to FreeRDP version 3.29.0 or later.
What types of attacks are associated with CVE-2026-67303?
CVE-2026-67303 is associated with Denial of Service attacks through serial device control.
When was CVE-2026-67303 published?
CVE-2026-67303 was published on August 1, 2026.
Which software is affected by CVE-2026-67303?
FreeRDP versions prior to 3.29.0 are affected by CVE-2026-67303.