VYPR
High severity7.5NVD Advisory· Published Aug 1, 2026· Updated Sep 8, 2026

CVE-2026-67304

CVE-2026-67304

Description

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails. Attackers can send malformed smartcard IRP requests with non-zero cReaders and truncated reader-state data to crash the process via null pointer access in free_reader_states functions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7

Patches

Vulnerability mechanics

References

3

News mentions

1