Skip to content
VulniPulse
Advisory severityMedium4.3Red Hat Linux

Medium [CVE-2026-67302] Denial of service in camera redirection due to divide-by-zero

This medium-severity Red Hat Linux advisory covers CVE-2026-67302 affecting Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-67302 Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
Red Hat LinuxRed Hat Enterprise Linux
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a divide-by-zero vulnerability in the rdpecam camera redirection client. ecam_dev_process_start_streams_request() parses a server-controlled CAM_MEDIA_TYPE_DESCRIPTION from a StartStreamsRequest PDU but validates only Format and Flags, not FrameRateDenominator.

When a malicious or compromised RDP server sends a StartStreamsRequest with FrameRateDenominator set to zero, ecam_encoder_context_init() (channels/rdpecam/client/encoding.c) computes FrameRateNumerator / FrameRateDenominator, causing an integer division by zero (SIGFPE) and termination of the FreeRDP client process.

Camera redirection must be enabled on the client for the channel to be reachable. Fixed in FreeRDP 3.29.0.

A flaw was found in FreeRDP, a remote desktop protocol client. A malicious or compromised RDP server can exploit this vulnerability by sending a specially crafted `StartStreamsRequest` with a zero value for `FrameRateDenominator`.

This vulnerability in FreeRDP affects clients with camera redirection enabled. A malicious RDP server could send a crafted `StartStreamsRequest` PDU, leading to a divide-by-zero error and client process termination, resulting in a denial of service.

Exploitation requires user interaction to connect to a compromised server with the vulnerable feature active.

Affected versions
  • < 3.29.0
  • < 3.28.0

Official advisory · high-confidence parse· fetched 28 days ago·verify at source

Fixed versions
  • 3.29.0

Official advisory · high-confidence parse· fetched 28 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • To mitigate this issue, disable camera redirection when connecting to untrusted RDP servers. This can be achieved by using the --disable-camera option with the xfreerdp client or by configuring FreeRDP to not enable camera redirection. Disabling this feature will prevent the use of camera redirection functionality.

Official advisory · high-confidence parse· fetched 28 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.