PT-2026-22014 · Freerdp+2 · Freerdp+2
Ehdgks0627
·
Published
2026-01-01
·
Updated
2026-05-11
·
CVE-2026-25997
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
FreeRDP versions prior to 3.23.0
Description
FreeRDP is a free implementation of the Remote Desktop Protocol. A heap use after free condition exists in the clipboard handling functionality. Specifically, the
xf clipboard format equal function reads memory that has already been freed by xf clipboard formats free during auto-reconnect within the cliprdr channel thread, while the X11 event thread concurrently iterates over it in xf clipboard changed. This occurs because xf clipboard formats free frees the lastSentFormats array while another thread is still accessing it.Recommendations
Update to version 3.23.0 or later.
Exploit
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freerdp
Linuxmint
Ubuntu