PT-2026-92066 · Freerdp+1 · Freerdp+1

·

CVE-2026-91947

·

Published

2026-09-15

·

Updated

2026-09-16

CVSS v4.0

7.7

High

VectorAV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions FreeRDP server versions prior to 3.31.0
Description A use-after-free issue exists in the DRDYNVC parser. This occurs when a channel pointer is dereferenced after the synchronization lock has been released. Authenticated clients can trigger a heap-use-after-free by racing AUDIN channel closure messages against DRDYNVC data parsing, leading to the access of freed channel objects.
Recommendations Update to version 3.31.0 or later.

Exploit

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91947
GHSA-6MPX-C8RJ-WHJ5

Affected Products

Freerdp
Ubuntu