CVE-2026-22855

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap out-of-bounds read occurs in the smartcard SetAttrib path when cbAttrLen does not match the actual NDR buffer length. This vulnerability is fixed in 3.20.1.
CVSS

No CVSS.

Configurations

No configuration.

History

14 Jan 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-14 18:16

Updated : 2026-01-14 18:16


NVD link : CVE-2026-22855

Mitre link : CVE-2026-22855

CVE.ORG link : CVE-2026-22855


JSON object : View

Products Affected

No product.

CWE
CWE-125

Out-of-bounds Read