PT-2026-22011 · Freerdp+2 · Freerdp+2

Ehdgks0627

·

Published

2026-01-01

·

Updated

2026-05-22

·

CVE-2026-25954

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.23.0
Description FreeRDP is a free implementation of the Remote Desktop Protocol. A flaw exists in the RAIL channel window management where the xf rail server local move size function dereferences a freed xfAppWindow pointer. This occurs because the xf rail get window function returns an unprotected pointer from the railWindows hash table, and the main thread can delete the window while the RAIL channel thread is still using the pointer.
Recommendations Update to version 3.23.0 or later.

Exploit

Fix

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2026-04148
CVE-2026-25954
GHSA-CC88-4J37-MW6J
OESA-2026-2439
OESA-2026-2440
OESA-2026-2441
OESA-2026-2442
OPENSUSE-SU-2026:10408-1
OPENSUSE-SU-2026:10611-1
OPENSUSE-SU-2026:20632-1
OPENSUSE-SU-2026:20657-1
SUSE-SU-2026:1632-1
SUSE-SU-2026:1633-1
SUSE-SU-2026:1634-1
SUSE-SU-2026:1635-1
SUSE-SU-2026:1640-1
SUSE-SU-2026:21436-1
USN-8105-1

Affected Products

Freerdp
Linuxmint
Ubuntu