PT-2026-22021 · Freerdp+3 · Freerdp+3

·

CVE-2026-27950

·

Published

2026-02-23

·

Updated

2026-06-15

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.23.0
Description FreeRDP is a free implementation of the Remote Desktop Protocol. A previous fix for a heap-use-after-free issue was incomplete. The vulnerable code exists in the SDL2 implementation, where a pointer is not nulled after being freed, potentially leading to a security issue. The fix was initially applied only to the SDL3 code path.
Recommendations Update to version 3.23.0 or later.

Exploit

Fix

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-04156
CVE-2026-27950
GHSA-RVFG-86CR-5R6P
SUSE-SU-2026:1633-1
USN-8105-1

Affected Products

Freerdp
Linuxmint
Red Os
Ubuntu