PT-2026-56434 · Freerdp+1 · Freerdp+1

·

CVE-2026-56297

·

Published

2026-07-08

·

Updated

2026-08-13

CVSS v4.0

8.3

High

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.22.0
Description A heap use-after-free occurs in the Dynamic Virtual Channel (drdynvc) handling path due to improper synchronization of channel callback access. A malicious RDP server can trigger a race condition by sending DYNVC DATA and DYNVC CLOSE messages concurrently, causing the dvcman channel close and dvcman call on receive functions to access freed memory in the drdynvc client thread. This can lead to a denial of service via a client crash or potentially enable remote code execution within the context of the client process.
Recommendations Update to version 3.22.0.

Exploit

Fix

RCE

DoS

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56297
GHSA-3MV2-5Q57-2V8H
SUSE-SU-2026:3562-1
USN-8561-1

Affected Products

Freerdp
Red Os