THREAT OPS › Threat News › [NVD] CVE-2026-67291 (HIGH 7.5) — FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-byte server-controlled declared fragm
[NVD] CVE-2026-67291 (HIGH 7.5) — FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-byte server-controlled declared fragm
CVE-2026-67291 CVSS: 7.5 HIGH Published: 2026-08-01T13:16:58.097
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-byte server-controlled declared fragment size but does not verify it fits within the remain
Indicators of compromise
- CVE-2026-67291cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-67291