PT-2026-22014 · Freerdp+2 · Freerdp+2

Ehdgks0627

·

Published

2026-01-01

·

Updated

2026-05-11

·

CVE-2026-25997

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.23.0
Description FreeRDP is a free implementation of the Remote Desktop Protocol. A heap use after free condition exists in the clipboard handling functionality. Specifically, the xf clipboard format equal function reads memory that has already been freed by xf clipboard formats free during auto-reconnect within the cliprdr channel thread, while the X11 event thread concurrently iterates over it in xf clipboard changed. This occurs because xf clipboard formats free frees the lastSentFormats array while another thread is still accessing it.
Recommendations Update to version 3.23.0 or later.

Exploit

Fix

Use After Free

Weakness Enumeration

Related Identifiers

ALSA-2026:16014
BDU:2026-04150
CVE-2026-25997
GHSA-Q5J3-M6JF-3JQ4
OESA-2026-1516
OESA-2026-1517
OESA-2026-1518
OESA-2026-1519
OESA-2026-1520
OESA-2026-1521
OPENSUSE-SU-2026:10408-1
OPENSUSE-SU-2026:10611-1
OPENSUSE-SU-2026:20632-1
OPENSUSE-SU-2026:20657-1
SUSE-SU-2026:1632-1
SUSE-SU-2026:1633-1
SUSE-SU-2026:1634-1
SUSE-SU-2026:1635-1
SUSE-SU-2026:1640-1
SUSE-SU-2026:21436-1
USN-8105-1

Affected Products

Freerdp
Linuxmint
Ubuntu