Fedora Account System
Red Hat Associate
Red Hat Customer
FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails. Attackers can send malformed smartcard IRP requests with non-zero cReaders and truncated reader-state data to crash the process via null pointer access in free_reader_states functions.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:61378 https://access.redhat.com/errata/RHSA-2026:61378
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:68706 https://access.redhat.com/errata/RHSA-2026:68706