Bug 2514346 (CVE-2026-73242) - CVE-2026-73242 FreeRDP: FreeRDP: Out-of-bounds memory access in Kerberos decryption
Summary: CVE-2026-73242 FreeRDP: FreeRDP: Out-of-bounds memory access in Kerberos decr...
Keywords:
Status: NEW
Alias: CVE-2026-73242
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
: CVE-2026-72745 (view as bug list)
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-11 20:01 UTC by OSIDB Bzimport
Modified: 2026-08-18 17:55 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-11 20:01:18 UTC
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos/kerberos.c kerberos_DecryptMessage function fails to bound the peer-controlled GSS Wrap-token EC field before using it with RRC in IOV pointer offsets, allowing a malicious RDP peer to trigger out-of-bounds reads and in-place writes during CredSSP/NLA Kerberos decryption. This issue is fixed in version 3.30.0.

Comment 2 Ganesh 2026-08-18 17:55:00 UTC
*** Bug 2513936 has been marked as a duplicate of this bug. ***


Note You need to log in before you can comment on or make changes to this bug.