Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-91947

Опубликовано: 15 сент. 2026
Источник: debian

Описание

FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock. Authenticated clients can race AUDIN channel closure messages against DRDYNVC data parsing to trigger heap-use-after-free when accessing freed channel objects.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
freerdp3fixed3.31.0+dfsg-1package
freerdp2removedpackage

Примечания

  • https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-6mpx-c8rj-whj5

  • https://www.openwall.com/lists/oss-security/2026/09/01/2

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 дня назад

[GHSA-6mpx-c8rj-whj5: FreeRDP server DRDYNVC parser use-after-free during concurrent channel close]

CVSS3: 7.5
redhat
4 дня назад

FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock. Authenticated clients can race AUDIN channel closure messages against DRDYNVC data parsing to trigger heap-use-after-free when accessing freed channel objects.

CVSS3: 7.5
nvd
4 дня назад

FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock. Authenticated clients can race AUDIN channel closure messages against DRDYNVC data parsing to trigger heap-use-after-free when accessing freed channel objects.

CVSS3: 7.5
github
4 дня назад

FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock. Authenticated clients can race AUDIN channel closure messages against DRDYNVC data parsing to trigger heap-use-after-free when accessing freed channel objects.