PT-2026-66344 · Freerdp · Freerdp

CVE-2026-63652

·

Published

2026-07-02

·

Updated

2026-09-07

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.28.0
Description In the rdpsnd server recv formats function within channels/rdpsnd/server/rdpsnd main.c, the software frees context->client formats when receiving a malformed Client Audio Formats PDU without clearing the owning pointer or num client formats. An authenticated RDP client can trigger an error, such as a cbSize larger than the remaining record, leaving a dangling pointer in the server context. This leads to a double-free condition when rdpsnd server context free is called during session teardown, which can cause heap corruption and terminate the server.
Recommendations Update to version 3.28.0 or later.

Exploit

Fix

DoS

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:61378
BDU:2026-12000
CVE-2026-63652
GHSA-9G22-W2GR-VCMP
OPENSUSE-SU-2026:11385-1

Affected Products

Freerdp