PT-2026-7043 · Freerdp+4 · Freerdp+4

·

CVE-2026-24684

·

Published

2026-01-01

·

Updated

2026-06-15

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.22.0
Description FreeRDP, a Remote Desktop Protocol implementation, contains a flaw in the RDPSND async playback thread. Specifically, the thread may process queued Protocol Data Units (PDUs) after the channel is closed and internal state is freed, resulting in a use-after-free condition within the rdpsnd treat wave function.
Recommendations Update to version 3.22.0 or later.

Exploit

Fix

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:6340
ALSA-2026:6799
ALSA-2026:6918
BDU:2026-10012
CVE-2026-24684
GHSA-VCGV-XGJP-H83Q
MGASA-2026-0046
OESA-2026-1516
OESA-2026-1517
OESA-2026-1518
OESA-2026-1519
OESA-2026-1520
OESA-2026-1521
OPENSUSE-SU-2026:10132-1
OPENSUSE-SU-2026:10243-1
OPENSUSE-SU-2026:20320-1
OPENSUSE-SU-2026:20339-1
OPENSUSE-SU-2026:20632-1
RHSA-2026:10076
RHSA-2026:10735
RHSA-2026:10951
RHSA-2026:11323
RHSA-2026:6340
RHSA-2026:6727
RHSA-2026:6743
RHSA-2026:6799
RHSA-2026:6918
RHSA-2026:6958
RHSA-2026:9640
RHSA-2026:9641
SUSE-SU-2026:0621-1
SUSE-SU-2026:0649-1
SUSE-SU-2026:0683-1
SUSE-SU-2026:0762-1
SUSE-SU-2026:0763-1
SUSE-SU-2026:1217-1
SUSE-SU-2026:1313-1
USN-8042-1

Affected Products

Freerdp
Linuxmint
Red Os
Rocky Linux
Ubuntu