CVE-2026-73242

Source
https://cve.org/CVERecord?id=CVE-2026-73242
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73242.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-73242
Aliases
Downstream
Related
Published
2026-08-11T19:49:46.974Z
Modified
2026-09-05T11:10:53.070763788Z
Severity
  • 8.3 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
FreeRDP: Kerberos GSS Wrap-token `EC` field is unbounded, causing an out-of-bounds decrypt in `kerberos_DecryptMessage`
Details

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos/kerberos.c kerberos_DecryptMessage function fails to bound the peer-controlled GSS Wrap-token EC field before using it with RRC in IOV pointer offsets, allowing a malicious RDP peer to trigger out-of-bounds reads and in-place writes during CredSSP/NLA Kerberos decryption. This issue is fixed in version 3.30.0.

Database specific
{
    "cwe_ids": [
        "CWE-122"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73242.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/freerdp/freerdp

Affected ranges

Type
GIT
Repo
https://github.com/freerdp/freerdp
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "3.30.0"
        }
    ]
}

Affected versions

1.*
1.0-beta1
1.0-beta2
1.0-beta4
1.0-beta5
1.0.0
1.0.1
1.1.0-beta+2013071101
1.1.0-beta1
1.1.0-beta1+android2
1.1.0-beta1+android3
1.1.0-beta1+android4
1.1.0-beta1+android5
1.1.0-beta1+ios1
1.1.0-beta1+ios2
1.1.0-beta1+ios3
1.1.0-beta1+ios4
1.2.0-beta1+android7
1.2.0-beta1+android9
2.*
2.0.0
2.0.0-beta1+android10
2.0.0-beta1+android11
2.0.0-rc0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
3.*
3.0.0
3.0.0-beta1
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-rc0
3.1.0
3.2.0
3.3.0
3.4.0
3.5.0
3.5.1

Database specific

vanir_signatures
[
    {
        "target": {
            "file": "winpr/libwinpr/sspi/Kerberos/kerberos.c",
            "function": "kerberos_DecryptMessage"
        },
        "deprecated": false,
        "id": "CVE-2026-73242-39af6bc6",
        "signature_version": "v1",
        "digest": {
            "function_hash": "20752489110586322077114707030220701721",
            "length": 2879.0
        },
        "signature_type": "Function",
        "source": "https://github.com/freerdp/freerdp/commit/0adf5e30d01be84e190a359a7bdd37bc51d740cc"
    },
    {
        "source": "https://github.com/freerdp/freerdp/commit/0adf5e30d01be84e190a359a7bdd37bc51d740cc",
        "deprecated": false,
        "id": "CVE-2026-73242-954d101c",
        "target": {
            "file": "winpr/libwinpr/sspi/Kerberos/kerberos.c"
        },
        "digest": {
            "line_hashes": [
                "183957588680473477111885932628843767782",
                "231088361886876251488551207803087798227",
                "63006503932412767430507127752573248074",
                "329799447752175624195799694795319345014",
                "193805627113040353652333127886014247092",
                "8587626814916815753257547874864517638",
                "272831188564292061182367270946121919404",
                "237317082912156103622325973657227737621",
                "124767322165091419577031892498288722683",
                "285697336184571110304970769060665436227",
                "270430341779912644669643416931438172717",
                "158310201793977989184814508062854777973",
                "243736110218934412148813667222058368889",
                "248464906151274659704344321894976601716",
                "165321435709860996306081406791928807554",
                "234501983744744827721762034058941485942",
                "941943334154895846805788121959270393",
                "119849275391800769881779500615008728847",
                "224497565397760830429365232098164137953",
                "47971582507313495506253211209008478342",
                "137372268561595661271739201975204607776",
                "189047672062284389162556040897660316098",
                "29158253664559196836857687789094467782",
                "265882997374180541219022085467650198537",
                "257046955521684084780166000111197101791",
                "76297737727143435437697746478657346234",
                "212358537045075951530568044984765281453",
                "205592017599283643521078321249097242272",
                "113347059671793557838922529341586558704",
                "258004701455541907780941177778692321129",
                "75690882133983941029281052433632631489",
                "22553972274089127750597373108851396948",
                "118455097896274688986598043796257710519",
                "228083363774025746360012232124998635776",
                "37748299209380672046570385352850092123",
                "88204766201819962262441352189682423296",
                "226389264167949580097158373932896704949",
                "299391362726505856823441550887802104903",
                "49426502543771717888696211549656504284",
                "270970795116785765650489596197903630727",
                "265879293666029473514438727488224268900",
                "110543645888629505955042539203774293180",
                "83793427006144309513378654315292147414"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line",
        "signature_version": "v1"
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73242.json"
vanir_signatures_modified
"2026-08-14T09:05:47Z"