PT-2026-7040 · Freerdp+4 · Freerdp+4
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
FreeRDP versions prior to 3.22.0
Description
FreeRDP, a Remote Desktop Protocol implementation, contains a flaw related to asynchronous bulk transfer completions. Specifically, the software can utilize a freed channel callback following a URBDRC channel closure, resulting in a use-after-free condition within the urb write completion function.
Recommendations
Update to version 3.22.0 or later.
Exploit
Fix
DoS
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freerdp
Linuxmint
Red Os
Rocky Linux
Ubuntu