Use-after-free in FreeRDP - #VU146578

 

Use-after-free in FreeRDP - #VU146578

Published: September 1, 2026


Vulnerability identifier: #VU146578
CSH Severity: Low
CVSS v4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service and potentially disclose sensitive information or modify data.

The vulnerability exists due to use-after-free in the server-side DRDYNVC parser when processing concurrent channel close and DRDYNVC data for the same dynamic virtual channel. A remote user can race channel-closing traffic with overlapping DRDYNVC data to cause a denial of service and potentially disclose sensitive information or modify data.

The server must enable a dynamic virtual channel whose worker can close it while the socket thread parses client data. The validated trigger uses AUDIN, and exploitation requires winning a race condition during channel close and parsing.


Affected software

FreeRDP

Remediation

Install security update from vendor's website.

FreeRDP - update to 3.31.0

External References

Related Security Bulletins