Description
FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can send malformed media format data from a server to trigger a crash by reading fixed offsets without validating source buffer length.
Published: 2026-08-01
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

FreeRDP prior to 3.29.0 contains a heap out‑of‑bounds read in the TSMF FFmpeg decoder. When parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData the decoder reads at fixed offsets without validating the source buffer length, causing a crash. This results in a loss of service for the affected client and may expose sensitive memory contents if the crash occurs during privileged execution.

Affected Systems

The vulnerable components are part of the FreeRDP project, version 3.29.0 and earlier. The issue affects users running any FreeRDP client that processes TSMF media streams, particularly those that accept AVC1 MPEG2VIDEOINFO formats, on any operating system supported by FreeRDP.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity vulnerability. An attacker can trigger the crash by sending a carefully crafted media format from a server to a FreeRDP client over the network; no elevated privileges are required on the client. EPSS information is not available and the vulnerability is not listed in CISA’s KEV catalog, but the lack of a public exploit does not mitigate the impact of the denial of service. Because the flaw is triggered by an external server, the risk remains high for clients that accept arbitrary media streams.

Generated by OpenCVE AI on August 2, 2026 at 03:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade FreeRDP to version 3.29.0 or later.
  • Disable or remove support for AVC1 MPEG2VIDEOINFO media types from the client configuration.
  • Configure the server to refuse or strip malformed media format data before transmission to clients.
  • Monitor application logs for unexpected crashes or memory read errors and investigate any anomalies.

Generated by OpenCVE AI on August 2, 2026 at 03:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 03 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 01 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can send malformed media format data from a server to trigger a crash by reading fixed offsets without validating source buffer length.
Title FreeRDP before 3.29.0 Heap Out-of-Bounds Read via TSMF
First Time appeared Freerdp
Freerdp freerdp
Weaknesses CWE-125
CPEs cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*
Vendors & Products Freerdp
Freerdp freerdp
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-03T15:38:23.740Z

Reserved: 2026-07-29T13:01:57.547Z

Link: CVE-2026-67290

cve-icon Vulnrichment

Updated: 2026-08-03T15:00:33.285Z

cve-icon NVD

Status : Received

Published: 2026-08-01T13:16:57.940

Modified: 2026-08-03T17:16:40.020

Link: CVE-2026-67290

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-01T12:22:16Z

Links: CVE-2026-67290 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T03:30:14Z

Weaknesses