REDHAT-BUG-2510001: Null Pointer Dereference
FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARDIOCTLREADCACHEA and SCARDIOCTLWRITECACHEA operations. When smartcard emulation is enabled, attackers can send crafted smartcard cache requests with NULL lookup-name pointers to trigger strlen() on a null pointer, causing client process termination.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FreeRDPto a version that resolves this vulnerability.Fixed in 3.29.0 - Configuration
Disable smartcard emulation so attackers cannot send crafted smartcard cache requests that trigger the NULL pointer dereference in smartcard cache request decoders for SCARD_IOCTL_READCACHEA/SCARD_IOCTL_WRITECACHEA.
FreeRDP smartcard emulation smartcard emulation = disabled