High severity7.5NVD Advisory· Published Aug 1, 2026· Updated Aug 31, 2026
CVE-2026-67290
CVE-2026-67290
Description
FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can send malformed media format data from a server to trigger a crash by reading fixed offsets without validating source buffer length.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
1- Freerdp: 21 Vulnerabilities Disclosed Together, Patch Released in 3.29.0Vypr Intelligence · Aug 2, 2026