Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-91947

Опубликовано: 15 сент. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock. Authenticated clients can race AUDIN channel closure messages against DRDYNVC data parsing to trigger heap-use-after-free when accessing freed channel objects.

A flaw was found in FreeRDP server. This use-after-free vulnerability exists in the DRDYNVC parser, where a channel pointer is dereferenced after its synchronization lock has been released. An authenticated client can exploit this by racing AUDIN channel closure messages against DRDYNVC data parsing, leading to memory corruption. This could potentially result in arbitrary code execution or a denial of service.

Меры по смягчению последствий

The vulnerability requires an authenticated client to interact with the FreeRDP server. To mitigate this issue, restrict network access to the FreeRDP server to only trusted clients and networks. If the FreeRDP server functionality is not required, consider disabling or uninstalling the FreeRDP server component to eliminate the attack surface.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freerdpAffected
Red Hat Enterprise Linux 6freerdpNot affected
Red Hat Enterprise Linux 7freerdpAffected
Red Hat Enterprise Linux 8freerdpAffected
Red Hat Enterprise Linux 9freerdpAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2533942FreeRDP: FreeRDP: Use-after-free vulnerability in DRDYNVC parser leads to memory corruption

EPSS

Процентиль: 23%
0.003
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 дня назад

[GHSA-6mpx-c8rj-whj5: FreeRDP server DRDYNVC parser use-after-free during concurrent channel close]

CVSS3: 7.5
nvd
4 дня назад

FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock. Authenticated clients can race AUDIN channel closure messages against DRDYNVC data parsing to trigger heap-use-after-free when accessing freed channel objects.

CVSS3: 7.5
debian
4 дня назад

FreeRDP server versions before 3.31.0 contain a use-after-free vulnera ...

CVSS3: 7.5
github
4 дня назад

FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock. Authenticated clients can race AUDIN channel closure messages against DRDYNVC data parsing to trigger heap-use-after-free when accessing freed channel objects.

EPSS

Процентиль: 23%
0.003
Низкий

7.5 High

CVSS3