FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, the RDPSND async playback thread can process queued PDUs after the channel is closed and internal state is freed, leading to a use after free in rdpsnd_treat_wave. This vulnerability is fixed in 3.22.0.
References
Configurations
History
10 Feb 2026, 15:02
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| First Time |
Freerdp
Freerdp freerdp |
|
| References | () https://github.com/FreeRDP/FreeRDP/commit/622bb7b4402491ca003f47472d0e478132673696 - Patch | |
| References | () https://github.com/FreeRDP/FreeRDP/commit/afa6851dc80835d3101e40fcef51b6c5c0f43ea5 - Patch | |
| References | () https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-vcgv-xgjp-h83q - Patch, Vendor Advisory |
09 Feb 2026, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-09 19:15
Updated : 2026-02-10 15:02
NVD link : CVE-2026-24684
Mitre link : CVE-2026-24684
CVE.ORG link : CVE-2026-24684
JSON object : View
Products Affected
freerdp
- freerdp
CWE
CWE-416
Use After Free
