PT-2026-2929 · Freerdp+3 · Freerdp+3
CVSS v4.0
8.2
High
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
FreeRDP versions prior to 3.20.1
Description
FreeRDP, a free implementation of the Remote Desktop Protocol, contains a flaw due to a race condition between the RDPGFX dynamic virtual channel thread and the SDL render thread. This condition results in a heap use-after-free issue. Specifically, a pointer to
sdl->primary (SDL Surface) is accessed after being freed during RDPGFX ResetGraphics handling.Recommendations
Update to version 3.20.1 or later.
Exploit
Fix
DoS
Race Condition
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freerdp
Linuxmint
Red Os
Ubuntu