PT-2026-3467 · Freerdp+4 · Freerdp+4

·

CVE-2026-23884

·

Published

2026-01-01

·

Updated

2026-06-11

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.21.0
Description FreeRDP, a free implementation of the Remote Desktop Protocol, contains a flaw where offscreen bitmap deletion results in the gdi->drawing pointer referencing freed memory. This creates a use-after-free condition when related update packets are received. A malicious server can exploit this to cause a client-side use after free, leading to a denial-of-service (DoS) condition and potential heap corruption, which may result in code execution depending on the allocator and heap layout. The gdi->drawing variable is involved in this issue.
Recommendations Update to version 3.21.0 or later.

Exploit

Fix

RCE

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:2048
ALSA-2026:2081
ALSA-2026:2222
BDU:2026-00662
CVE-2026-23884
GHSA-CFGJ-VC84-F3PP
MGASA-2026-0086
OESA-2026-1516
OESA-2026-1517
OESA-2026-1518
OESA-2026-1519
OESA-2026-1520
OESA-2026-1521
OPENSUSE-SU-2026:10107-1
OPENSUSE-SU-2026:10459-1
OPENSUSE-SU-2026:20339-1
OPENSUSE-SU-2026:20632-1
RHSA-2026:2048
RHSA-2026:2081
RHSA-2026:2222
RHSA-2026:2714
RHSA-2026:2736
RHSA-2026:2770
RHSA-2026:2824
RHSA-2026:2952
RHSA-2026:3036
RHSA-2026:3037
RHSA-2026:3038
RHSA-2026:3039
RHSA-2026:3041
SUSE-SU-2026:0345-1
SUSE-SU-2026:0656-1
SUSE-SU-2026:0683-1
SUSE-SU-2026:0761-1
SUSE-SU-2026:0762-1
USN-8105-1

Affected Products

Freerdp
Linuxmint
Red Os
Rocky Linux
Ubuntu