CVE-2026-67304
Received Received - Intake

Null Pointer Dereference in FreeRDP Smartcard Handling

Vulnerability report for CVE-2026-67304, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-01

Last updated on: 2026-08-01

Assigner: VulnCheck

Description

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails. Attackers can send malformed smartcard IRP requests with non-zero cReaders and truncated reader-state data to crash the process via null pointer access in free_reader_states functions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-01
Last Modified
2026-08-01
Generated
2026-08-01
AI Q&A
2026-08-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
freerdp freerdp to 3.29.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

FreeRDP before version 3.29.0 has a null pointer dereference flaw in smartcard device handling. When processing smartcard IRP requests, if reader-state decoding fails, the cleanup function may access a null pointer, causing a crash. Attackers can exploit this by sending malformed requests with non-zero reader counts and truncated reader-state data.

Detection Guidance

Detection involves monitoring for malformed smartcard IRP requests or crashes in FreeRDP processes. Check FreeRDP logs for null pointer dereference errors or process crashes related to smartcard handling. Use network monitoring tools to inspect for unusual smartcard protocol traffic targeting FreeRDP services.

Impact Analysis

This vulnerability can cause denial-of-service by crashing FreeRDP processes, potentially disrupting remote desktop sessions. If exploited repeatedly, it may lead to service unavailability for users relying on FreeRDP for remote access.

Mitigation Strategies

Upgrade FreeRDP to version 3.29.0 or later to address the null pointer dereference flaw. If immediate upgrade is not possible, disable smartcard redirection in FreeRDP configurations or block malformed smartcard IRP requests at the network perimeter until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-67304. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart