PT-2026-7041 · Freerdp+3 · Freerdp+3

·

CVE-2026-24682

·

Published

2026-01-01

·

Updated

2026-06-15

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.22.0
Description FreeRDP, a Remote Desktop Protocol implementation, contains a flaw where the audin server recv formats function incorrectly calculates the number of audio formats to free upon parse failure. Specifically, it frees i + i formats, which can lead to an out-of-bounds access within the audio formats free function.
Recommendations Update to version 3.22.0 or later.

Exploit

Fix

DoS

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:6799
BDU:2026-10010
CVE-2026-24682
GHSA-VCW2-PQGW-MX6G
MGASA-2026-0046
OESA-2026-1516
OESA-2026-1517
OESA-2026-1518
OESA-2026-1519
OESA-2026-1520
OESA-2026-1521
OPENSUSE-SU-2026:10132-1
OPENSUSE-SU-2026:10243-1
OPENSUSE-SU-2026:20320-1
OPENSUSE-SU-2026:20339-1
RHSA-2026:6743
RHSA-2026:6799
SUSE-SU-2026:0621-1
SUSE-SU-2026:0649-1
SUSE-SU-2026:0683-1
SUSE-SU-2026:0762-1
SUSE-SU-2026:0763-1
USN-8042-1

Affected Products

Freerdp
Linuxmint
Red Os
Ubuntu