rail_server_handle_messages of the file channels/rail/server/rail_main.c of the component RAIL Channel Handler. The manipulation of the argument orderLength results in heap-based buffer overflow.
This vulnerability is cataloged as CVE-2026-67298. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
Intelligence View
⚡ tsecurity.de Intelligence
CVE-2026-67298 | FreeRDP up to 3.28.0 RAIL Channel rail_main.c rail_server_handle_messages orderLength heap-based overflow (EUVD-2026-51824 / Nessus ID 331622)
Reagiere als Erste:r — dein Feedback zählt!
A vulnerability, which was classified as critical, was found in FreeRDP up to 3.28.0. Affected by this issue is the function
SOCIAL SHARE CARD GENERATOR