{"id":"CVE-2026-73242","summary":"FreeRDP: Kerberos GSS Wrap-token `EC` field is unbounded, causing an out-of-bounds decrypt in `kerberos_DecryptMessage`","details":"FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos/kerberos.c kerberos_DecryptMessage function fails to bound the peer-controlled GSS Wrap-token EC field before using it with RRC in IOV pointer offsets, allowing a malicious RDP peer to trigger out-of-bounds reads and in-place writes during CredSSP/NLA Kerberos decryption. This issue is fixed in version 3.30.0.","aliases":["CVE-2026-72745","GHSA-vv64-95pc-vj9v"],"modified":"2026-09-05T11:10:53.070763788Z","published":"2026-08-11T19:49:46.974Z","related":["ALSA-2026:61378"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73242.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-122"]},"references":[{"type":"WEB","url":"https://github.com/FreeRDP/FreeRDP/releases/tag/3.30.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73242.json"},{"type":"ADVISORY","url":"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-vv64-95pc-vj9v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73242"},{"type":"FIX","url":"https://github.com/FreeRDP/FreeRDP/commit/0adf5e30d01be84e190a359a7bdd37bc51d740cc"},{"type":"FIX","url":"https://github.com/FreeRDP/FreeRDP/pull/13065"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/freerdp/freerdp","events":[{"introduced":"0"},{"fixed":"0adf5e30d01be84e190a359a7bdd37bc51d740cc"},{"fixed":"6b107f0aadbabc47941c5a5b893b88c01792af6d"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"3.30.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["3.5.1","3.5.0","3.4.0","3.3.0","3.2.0","3.1.0","3.0.0","3.0.0-rc0","3.0.0-beta4","3.0.0-beta3","3.0.0-beta2","3.0.0-beta1","2.0.0","2.0.0-rc4","2.0.0-rc3","2.0.0-rc2","2.0.0-rc1","2.0.0-rc0","2.0.0-beta1+android11","2.0.0-beta1+android10","1.2.0-beta1+android9","1.2.0-beta1+android7","1.1.0-beta+2013071101","1.1.0-beta1+ios4","1.1.0-beta1+android5","1.1.0-beta1+android4","1.1.0-beta1+ios3","1.1.0-beta1+ios2","1.1.0-beta1+android3","1.1.0-beta1+android2","1.1.0-beta1+ios1","1.1.0-beta1","1.0.1","1.0.0","1.0-beta5","1.0-beta4","1.0-beta2","1.0-beta1"],"database_specific":{"vanir_signatures_modified":"2026-08-14T09:05:47Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"20752489110586322077114707030220701721","length":2879},"id":"CVE-2026-73242-39af6bc6","signature_type":"Function","signature_version":"v1","source":"https://github.com/freerdp/freerdp/commit/0adf5e30d01be84e190a359a7bdd37bc51d740cc","target":{"file":"winpr/libwinpr/sspi/Kerberos/kerberos.c","function":"kerberos_DecryptMessage"}},{"target":{"file":"winpr/libwinpr/sspi/Kerberos/kerberos.c"},"deprecated":false,"digest":{"line_hashes":["183957588680473477111885932628843767782","231088361886876251488551207803087798227","63006503932412767430507127752573248074","329799447752175624195799694795319345014","193805627113040353652333127886014247092","8587626814916815753257547874864517638","272831188564292061182367270946121919404","237317082912156103622325973657227737621","124767322165091419577031892498288722683","285697336184571110304970769060665436227","270430341779912644669643416931438172717","158310201793977989184814508062854777973","243736110218934412148813667222058368889","248464906151274659704344321894976601716","165321435709860996306081406791928807554","234501983744744827721762034058941485942","941943334154895846805788121959270393","119849275391800769881779500615008728847","224497565397760830429365232098164137953","47971582507313495506253211209008478342","137372268561595661271739201975204607776","189047672062284389162556040897660316098","29158253664559196836857687789094467782","265882997374180541219022085467650198537","257046955521684084780166000111197101791","76297737727143435437697746478657346234","212358537045075951530568044984765281453","205592017599283643521078321249097242272","113347059671793557838922529341586558704","258004701455541907780941177778692321129","75690882133983941029281052433632631489","22553972274089127750597373108851396948","118455097896274688986598043796257710519","228083363774025746360012232124998635776","37748299209380672046570385352850092123","88204766201819962262441352189682423296","226389264167949580097158373932896704949","299391362726505856823441550887802104903","49426502543771717888696211549656504284","270970795116785765650489596197903630727","265879293666029473514438727488224268900","110543645888629505955042539203774293180","83793427006144309513378654315292147414"],"threshold":0.9},"id":"CVE-2026-73242-954d101c","signature_type":"Line","signature_version":"v1","source":"https://github.com/freerdp/freerdp/commit/0adf5e30d01be84e190a359a7bdd37bc51d740cc"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73242.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N"}]}