Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-67299

Опубликовано: 01 авг. 2026
Источник: redhat
CVSS3: 6.5

Описание

FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled (e.g. xfreerdp /async-update). In update_message_WindowIcon() a shallow CopyMemory() overwrites a freshly allocated lParam->iconInfo with the parser-owned windowIcon->iconInfo pointer. After the parser callback returns, update_recv_window_info_order() frees window_icon.iconInfo, but the queued async message still retains and later dispatches that stale pointer. A malicious or compromised RDP server sending a crafted RAIL Window Alternate Secondary Order with WINDOW_ORDER_ICON can trigger use-after-free, leading to memory corruption and client crash.

A flaw was found in FreeRDP. A malicious or compromised Remote Desktop Protocol (RDP) server can exploit a heap use-after-free vulnerability when a client connects with asynchronous updates enabled. By sending a specially crafted Window Alternate Secondary Order message, the server can trigger memory corruption, leading to a client crash and a denial of service.

Отчет

This is a Moderate client-side flaw in FreeRDP. When a user connects to a malicious RDP server with asynchronous updates explicitly enabled, a heap use-after-free vulnerability can be triggered. This leads to memory corruption and a denial of service on the client system, but requires user interaction with a compromised server.

Меры по смягчению последствий

To mitigate this issue, avoid connecting to untrusted RDP servers. Additionally, refrain from using the /async-update command-line option when launching FreeRDP clients, as this feature is required to trigger the vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6freerdpOut of support scope
Red Hat Enterprise Linux 7freerdpAffected
Red Hat Enterprise Linux 10freerdpFixedRHSA-2026:5448613.08.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportfreerdpFixedRHSA-2026:5871124.08.2026
Red Hat Enterprise Linux 8freerdpFixedRHSA-2026:5448513.08.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportfreerdpFixedRHSA-2026:6017326.08.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnfreerdpFixedRHSA-2026:6017326.08.2026
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportfreerdpFixedRHSA-2026:6125031.08.2026
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-OnfreerdpFixedRHSA-2026:6125031.08.2026
Red Hat Enterprise Linux 8.8 Telecommunications Update ServicefreerdpFixedRHSA-2026:6125131.08.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2509985FreeRDP: FreeRDP: Denial of Service via crafted WindowIcon async message

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled (e.g. xfreerdp /async-update). In update_message_WindowIcon() a shallow CopyMemory() overwrites a freshly allocated lParam->iconInfo with the parser-owned windowIcon->iconInfo pointer. After the parser callback returns, update_recv_window_info_order() frees window_icon.iconInfo, but the queued async message still retains and later dispatches that stale pointer. A malicious or compromised RDP server sending a crafted RAIL Window Alternate Secondary Order with WINDOW_ORDER_ICON can trigger use-after-free, leading to memory corruption and client crash.

CVSS3: 7.5
nvd
около 1 месяца назад

FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled (e.g. xfreerdp /async-update). In update_message_WindowIcon() a shallow CopyMemory() overwrites a freshly allocated lParam->iconInfo with the parser-owned windowIcon->iconInfo pointer. After the parser callback returns, update_recv_window_info_order() frees window_icon.iconInfo, but the queued async message still retains and later dispatches that stale pointer. A malicious or compromised RDP server sending a crafted RAIL Window Alternate Secondary Order with WINDOW_ORDER_ICON can trigger use-after-free, leading to memory corruption and client crash.

CVSS3: 7.5
debian
около 1 месяца назад

FreeRDP before 3.29.0 contains a client-side heap use-after-free in th ...

CVSS3: 7.5
github
около 1 месяца назад

FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled (e.g. xfreerdp /async-update). In update_message_WindowIcon() a shallow CopyMemory() overwrites a freshly allocated lParam->iconInfo with the parser-owned windowIcon->iconInfo pointer. After the parser callback returns, update_recv_window_info_order() frees window_icon.iconInfo, but the queued async message still retains and later dispatches that stale pointer. A malicious or compromised RDP server sending a crafted RAIL Window Alternate Secondary Order with WINDOW_ORDER_ICON can trigger use-after-free, leading to memory corruption and client crash.

CVSS3: 7.5
fstec
около 2 месяцев назад

Уязвимость функции update_message_WindowIcon() RDP-клиента FreeRDP, позволяющая нарушителю вызвать повреждение памяти и отказ в обслуживании

6.5 Medium

CVSS3