PT-2026-7125 · Freerdp+4 · Freerdp+4

·

CVE-2026-23948

·

Published

2026-01-01

·

Updated

2026-06-24

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.22.0
Description FreeRDP, a free implementation of the Remote Desktop Protocol, contains a flaw. A NULL pointer dereference exists in the rdp write logon info v2() function. A malicious RDP server can exploit this by sending a specially crafted LogonInfoV2 Protocol Data Unit (PDU) where cbDomain or cbUserName is set to 0, potentially causing a FreeRDP proxy to crash.
Recommendations Update to version 3.22.0 or later.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:6340
ALSA-2026:6799
ALSA-2026:6918
BDU:2026-10004
CVE-2026-23948
GHSA-6F3C-QVQQ-2PX5
MGASA-2026-0046
OESA-2026-2721
OPENSUSE-SU-2026:10132-1
OPENSUSE-SU-2026:20339-1
RHSA-2026:10076
RHSA-2026:10734
RHSA-2026:10735
RHSA-2026:10951
RHSA-2026:11323
RHSA-2026:19033
RHSA-2026:6340
RHSA-2026:6727
RHSA-2026:6743
RHSA-2026:6799
RHSA-2026:6918
RHSA-2026:6958
RHSA-2026:9640
RHSA-2026:9641
USN-8042-1

Affected Products

Freerdp
Linuxmint
Red Os
Rocky Linux
Ubuntu