


Perceptive Security
SOC/SIEM Consultancy

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfree…
Published:
1 augustus 2026 om 00:00:00
Alert date:
1 augustus 2026 om 16:10:40
Source:
nvd.nist.gov
Network Infrastructure, Zero-Day Vulnerabilities
FreeRDP versions 3.28.0 and earlier contain a heap out-of-bounds read vulnerability in the update_process_glyph_fragments() and glyph_cache_fragment_put() functions within libfreerdp/cache/glyph.c. The flaw arises when handling a GLYPH_FRAGMENT_ADD update, where the code reads a server-controlled one-byte declared fragment size without validating it against the remaining buffer length. A malicious RDP server can exploit this by sending a short fragment with an inflated declared size, causing the client to read beyond the allocated heap buffer. The result is an out-of-bounds read that leads to a client crash. The vulnerability is fixed in FreeRDP 3.29.0. A patch is available via the official FreeRDP GitHub repository. The issue has also been documented in a GitHub Security Advisory (GHSA-hgj8-g595-wfc6) and tracked by VulnCheck.
Technical details
Mitigation steps:
Affected products:
FreeRDP <= 3.28.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67291
https://github.com/FreeRDP/FreeRDP/commit/f3b4347105114fe7453828736bea069999af319f
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-hgj8-g595-wfc6
https://www.vulncheck.com/advisories/freerdp-before-heap-out-of-bounds-read-via-glyph-fragment-add
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
