Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-25953

Опубликовано: 25 фев. 2026
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, xf_AppUpdateWindowFromSurface reads from a freed xfAppWindow because the RDPGFX DVC thread obtains a bare pointer via xf_rail_get_window without any lifetime protection, while the main thread can concurrently delete the window through a fastpath window-delete order. Version 3.23.0 fixes the issue.

A flaw was found in FreeRDP, a free implementation of the Remote Desktop Protocol. This use-after-free vulnerability occurs in the xf_AppUpdateWindowFromSurface function where a bare pointer to a window is obtained without proper lifetime protection. A remote attacker could exploit this by concurrently deleting the window while it is being accessed, leading to a read from freed memory. This could result in a denial of service (DoS) for the affected system.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freerdpFix deferred
Red Hat Enterprise Linux 6freerdpFix deferred
Red Hat Enterprise Linux 7freerdpFix deferred
Red Hat Enterprise Linux 8freerdpFix deferred
Red Hat Enterprise Linux 9freerdpFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2442757freerdp: FreeRDP: Denial of Service due to use-after-free vulnerability in window handling

EPSS

Процентиль: 44%
0.00587
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
5 месяцев назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_AppUpdateWindowFromSurface` reads from a freed `xfAppWindow` because the RDPGFX DVC thread obtains a bare pointer via `xf_rail_get_window` without any lifetime protection, while the main thread can concurrently delete the window through a fastpath window-delete order. Version 3.23.0 fixes the issue.

CVSS3: 9.8
nvd
5 месяцев назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_AppUpdateWindowFromSurface` reads from a freed `xfAppWindow` because the RDPGFX DVC thread obtains a bare pointer via `xf_rail_get_window` without any lifetime protection, while the main thread can concurrently delete the window through a fastpath window-delete order. Version 3.23.0 fixes the issue.

CVSS3: 9.8
debian
5 месяцев назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

CVSS3: 9.8
fstec
5 месяцев назад

Уязвимость функции xf_AppUpdateWindowFromSurface() RDP-клиента FreeRDP, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 9.8
redos
около 2 месяцев назад

Уязвимость freerdp3

EPSS

Процентиль: 44%
0.00587
Низкий

4.3 Medium

CVSS3