PT-2026-2937 · Freerdp+3 · Freerdp+3

·

CVE-2026-22857

·

Published

2026-01-01

·

Updated

2026-06-11

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.20.1
Description FreeRDP is a free implementation of the Remote Desktop Protocol. A heap use-after-free condition exists in the irp thread func function because the IRP is freed by irp->Complete() and subsequently accessed again during error handling.
Recommendations Update to version 3.20.1 or later.

Exploit

Fix

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-00619
CVE-2026-22857
GHSA-4GXQ-JHQ6-4CR8
MGASA-2026-0086
OESA-2026-1516
OESA-2026-1517
OESA-2026-1518
OESA-2026-1519
OESA-2026-1520
OESA-2026-1521
OPENSUSE-SU-2026:10059-1
OPENSUSE-SU-2026:10459-1
OPENSUSE-SU-2026:20339-1
OPENSUSE-SU-2026:20632-1
SUSE-SU-2026:0345-1
SUSE-SU-2026:0656-1
SUSE-SU-2026:0683-1
SUSE-SU-2026:0761-1
SUSE-SU-2026:0762-1
USN-8105-1

Affected Products

Freerdp
Linuxmint
Red Os
Ubuntu