F
reeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, the RDPSND async playback thread can process queued PDUs after the channel is closed and internal state is freed, leading to a use after free in rdpsnd_treat_wave. This vulnerability is fixed in 3.22.0.
References
Configurations
History
10 Feb 2026, 15:02
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| References | () https://github.com/FreeRDP/FreeRDP/commit/622bb7b4402491ca003f47472d0e478132673696 - Patch | |
| References | () https://github.com/FreeRDP/FreeRDP/commit/afa6851dc80835d3101e40fcef51b6c5c0f43ea5 - Patch | |
| References | () https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-vcgv-xgjp-h83q - Patch, Vendor Advisory | |
| CPE | cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:* | |
| First Time |
Freerdp
Freerdp freerdp |
09 Feb 2026, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-09 19:15
Updated : 2026-02-10 15:02
NVD link : CVE-2026-24684
Mitre link : CVE-2026-24684
CVE.ORG link : CVE-2026-24684
JSON object : View
CWE
CWE-416
Use After Free