CVE-2026-67296
PoC largeUnauthenticated Remote DoS in FreeRDP RDPEI Server Channel Handling
FreeRDP before 3.29.0 fails to validate the maximum PDU body length in its RDPEI (RDP input extension) server channel handler before allocating a stream, enabling memory exhaustion. A malicious RDP client can connect to a FreeRDP-based RDP server and send a header-only RDPEI message declaring an oversized body length, forcing the server to allocate excessive memory and crash or stall the service. An attacker gains unauthenticated remote denial of service with no confidentiality or integrity impact, per the CVSS 4.0 vector (VA:H only). All FreeRDP releases prior to 3.29.0 are affected, but only deployments acting as RDP servers that accept connections from untrusted clients (e.g., shadow server, products embedding FreeRDP server libraries) are realistically exposed. No exploitation has been reported in the wild and the flaw is absent from CISA KEV; a public vendor security advisory (GHSA-jm8r-22j6-4m4v) exists and EPSS is low at 0.3%.
What to do: Upgrade FreeRDP to 3.29.0 or later, or install vendor/distribution backported packages. Operators running FreeRDP-based RDP servers (e.g., freerdp-shadow or products embedding the server libraries) should restrict RDP listener exposure with firewall rules or VPN access and watch for memory-exhaustion crashes. Verify the deployed version via package changelogs or 'freerdp --version' to confirm the fix is present.
| FreeRDP | all versions before 3.29.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large declared body length to force excessive memory allocation on the server.
- Vendors
- freerdp
- Products
- freerdp
- Weakness
- CWE-20
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.