Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56297

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 5.6

Описание

FreeRDP before 3.22.0 contains a use-after-free vulnerability in dvcman_channel_close and dvcman_call_on_receive due to improper synchronization of channel_callback access. A malicious RDP server can trigger a race condition by sending DYNVC_DATA and DYNVC_CLOSE messages concurrently, causing heap-use-after-free in the drdynvc client thread and potentially enabling remote code execution or denial of service.

A flaw was found in FreeRDP. A malicious Remote Desktop Protocol (RDP) server can exploit a use-after-free vulnerability due to improper synchronization of channel callback access. By sending DYNVC_DATA and DYNVC_CLOSE messages concurrently, a race condition can be triggered in the drdynvc client thread, leading to heap-use-after-free. This could potentially enable remote code execution or cause a denial of service.

Отчет

This Moderate impact flaw in FreeRDP allows a malicious RDP server to trigger a use-after-free condition on the client by exploiting a race condition during dynamic virtual channel closure. This could lead to remote code execution or denial of service on the client system when connecting to a compromised or untrusted RDP server.

Меры по смягчению последствий

Configure host-based firewalls (e.g., firewalld) or network egress filtering so that the workstation can only initiate outbound RDP connections (typically TCP 3389) to known, trusted internal RDP gateways or corporate servers. Blocking outbound RDP to the wider internet neutralizes the threat of users accidentally connecting to malicious external endpoints.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freerdpAffected
Red Hat Enterprise Linux 6freerdpOut of support scope
Red Hat Enterprise Linux 7freerdpAffected
Red Hat Enterprise Linux 8freerdpAffected
Red Hat Enterprise Linux 9freerdpAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-364
https://bugzilla.redhat.com/show_bug.cgi?id=2498073FreeRDP: FreeRDP: Remote code execution or denial of service via use-after-free race condition

5.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 7
ubuntu
27 дней назад

FreeRDP before 3.22.0 contains a use-after-free vulnerability in dvcman_channel_close and dvcman_call_on_receive due to improper synchronization of channel_callback access. A malicious RDP server can trigger a race condition by sending DYNVC_DATA and DYNVC_CLOSE messages concurrently, causing heap-use-after-free in the drdynvc client thread and potentially enabling remote code execution or denial of service.

CVSS3: 7
nvd
27 дней назад

FreeRDP before 3.22.0 contains a use-after-free vulnerability in dvcman_channel_close and dvcman_call_on_receive due to improper synchronization of channel_callback access. A malicious RDP server can trigger a race condition by sending DYNVC_DATA and DYNVC_CLOSE messages concurrently, causing heap-use-after-free in the drdynvc client thread and potentially enabling remote code execution or denial of service.

CVSS3: 7
debian
27 дней назад

FreeRDP before 3.22.0 contains a use-after-free vulnerability in dvcma ...

CVSS3: 7
github
27 дней назад

FreeRDP before 3.22.0 contains a use-after-free vulnerability in dvcman_channel_close and dvcman_call_on_receive due to improper synchronization of channel_callback access. A malicious RDP server can trigger a race condition by sending DYNVC_DATA and DYNVC_CLOSE messages concurrently, causing heap-use-after-free in the drdynvc client thread and potentially enabling remote code execution or denial of service.

5.6 Medium

CVSS3