


Perceptive Security
SOC/SIEM Consultancy

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails. Attackers …
Published:
1 August 2026 at 00:00:00
Alert date:
1 August 2026 at 16:11:13
Source:
nvd.nist.gov
Network Infrastructure, Enterprise Applications
FreeRDP versions before 3.29.0 are affected by a null pointer dereference vulnerability in the smartcard device control request cleanup process. The flaw is triggered when reader-state decoding fails during handling of smartcard IRP requests. Attackers can exploit this by sending malformed smartcard IRP requests containing non-zero cReaders values paired with truncated reader-state data. This causes a null pointer access in the free_reader_states functions, resulting in a process crash. The vulnerability enables remote denial-of-service attacks against systems using FreeRDP with smartcard redirection enabled. A fix has been issued in FreeRDP version 3.29.0. The vulnerability is tracked under CVE-2026-67304 and has been documented in a GitHub security advisory. Patch details are available via the referenced GitHub commit.
Technical details
Mitigation steps:
Affected products:
FreeRDP
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67304
https://github.com/FreeRDP/FreeRDP/commit/1cc783d4c78bd2f66d3a8582dfe70a663d141444
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-78jj-45vh-jpm5
https://www.vulncheck.com/advisories/freerdp-before-null-dereference-via-smartcard-cleanup
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
