Unrated severityNVD Advisory· Published Aug 2, 2026
Debian freerdp3: FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI se…
CVE-2026-67296
Description
FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large declared body length to force excessive memory allocation on the server.
Affected products
2Patches
Vulnerability mechanics
News mentions
0No linked articles in our index yet.