PT-2026-22020 · Freerdp+3 · Freerdp+3

·

CVE-2026-26986

·

Published

2026-01-01

·

Updated

2026-05-19

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.23.0
Description FreeRDP is a free implementation of the Remote Desktop Protocol. A flaw exists where the rail window free function dereferences a freed xfAppWindow pointer during HashTable Free cleanup. This occurs because xf rail window common calls free(appWindow) on title allocation failure without first removing the entry from the railWindows hash table, resulting in a dangling pointer that is freed again on disconnect.
Recommendations Update to version 3.23.0 or later.

Exploit

Fix

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:16014
ALSA-2026:16019
ALSA-2026:16482
ALSA-2026:19358
BDU:2026-04154
CVE-2026-26986
GHSA-CRQX-G6X5-RX47
OESA-2026-1516
OESA-2026-1517
OESA-2026-1518
OESA-2026-1519
OESA-2026-1520
OESA-2026-1521
OPENSUSE-SU-2026:10611-1
OPENSUSE-SU-2026:20632-1
RHSA-2026:16014
RHSA-2026:16019
RHSA-2026:16482
RHSA-2026:16483
RHSA-2026:16485
RHSA-2026:16777
RHSA-2026:16814
RHSA-2026:16865
RHSA-2026:16866
SUSE-SU-2026:1632-1
SUSE-SU-2026:1633-1
SUSE-SU-2026:1634-1
SUSE-SU-2026:1635-1
SUSE-SU-2026:1640-1
USN-8105-1

Affected Products

Freerdp
Linuxmint
Rocky Linux
Ubuntu