Use-after-free in FreeRDP - #VU146578
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service and potentially disclose sensitive information or modify data.
The vulnerability exists due to use-after-free in the server-side DRDYNVC parser when processing concurrent channel close and DRDYNVC data for the same dynamic virtual channel. A remote user can race channel-closing traffic with overlapping DRDYNVC data to cause a denial of service and potentially disclose sensitive information or modify data.
The server must enable a dynamic virtual channel whose worker can close it while the socket thread parses client data. The validated trigger uses AUDIN, and exploitation requires winning a race condition during channel close and parsing.