Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-91957

Опубликовано: 15 сент. 2026
Источник: redhat
CVSS3: 3.1
EPSS Низкий

Описание

FreeRDP before 3.31.0 contains a use-after-free vulnerability in the smartcard RDPDR device handler when worker thread creation fails after device registration. Attackers can trigger thread creation failure during channel setup to cause device pointer deallocation while devman retains a reference, leading to crash or code execution.

A flaw was found in FreeRDP, a free implementation of the Remote Desktop Protocol (RDP). This use-after-free vulnerability exists in the smartcard RDPDR device handler. A remote attacker could exploit this by triggering a worker thread creation failure after device registration during channel setup. This leads to the deallocation of a device pointer while the device manager (devman) still retains a reference, which can result in a denial of service (crash) or potentially lead to arbitrary code execution.

Меры по смягчению последствий

To reduce the attack surface, disable smartcard redirection within FreeRDP client configurations if this functionality is not required. This action prevents the vulnerable smartcard RDPDR device handler from being utilized. Refer to FreeRDP documentation for specific instructions on disabling smartcard redirection.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freerdpFix deferred
Red Hat Enterprise Linux 6freerdpOut of support scope
Red Hat Enterprise Linux 7freerdpFix deferred
Red Hat Enterprise Linux 8freerdpFix deferred
Red Hat Enterprise Linux 9freerdpFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2533939FreeRDP: FreeRDP: Use-after-free vulnerability in smartcard RDPDR device handler leading to denial of service or potential code execution

EPSS

Процентиль: 26%
0.00327
Низкий

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 3.1
ubuntu
4 дня назад

[GHSA-j5mq-3349-gwmm: channels,smartcard worker creation failure frees a devman-owned device]

CVSS3: 3.1
nvd
4 дня назад

FreeRDP before 3.31.0 contains a use-after-free vulnerability in the smartcard RDPDR device handler when worker thread creation fails after device registration. Attackers can trigger thread creation failure during channel setup to cause device pointer deallocation while devman retains a reference, leading to crash or code execution.

CVSS3: 3.1
debian
4 дня назад

FreeRDP before 3.31.0 contains a use-after-free vulnerability in the s ...

CVSS3: 3.1
github
4 дня назад

FreeRDP before 3.31.0 contains a use-after-free vulnerability in the smartcard RDPDR device handler when worker thread creation fails after device registration. Attackers can trigger thread creation failure during channel setup to cause device pointer deallocation while devman retains a reference, leading to crash or code execution.

EPSS

Процентиль: 26%
0.00327
Низкий

3.1 Low

CVSS3