PT-2026-2929 · Freerdp+3 · Freerdp+3

·

CVE-2026-22851

·

Published

2026-01-01

·

Updated

2026-06-11

CVSS v4.0

8.2

High

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.20.1
Description FreeRDP, a free implementation of the Remote Desktop Protocol, contains a flaw due to a race condition between the RDPGFX dynamic virtual channel thread and the SDL render thread. This condition results in a heap use-after-free issue. Specifically, a pointer to sdl->primary (SDL Surface) is accessed after being freed during RDPGFX ResetGraphics handling.
Recommendations Update to version 3.20.1 or later.

Exploit

Fix

DoS

Race Condition

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-00623
CVE-2026-22851
GHSA-8G87-6PVC-WH99
OPENSUSE-SU-2026:10059-1
OPENSUSE-SU-2026:20339-1
SUSE-SU-2026:0345-1
USN-8105-1

Affected Products

Freerdp
Linuxmint
Red Os
Ubuntu