Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-91947

Опубликовано: 16 сент. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.5

Описание

[GHSA-6mpx-c8rj-whj5: FreeRDP server DRDYNVC parser use-after-free during concurrent channel close]

РелизСтатусПримечание
devel

DNE

esm-apps/bionic

needs-triage

esm-infra-legacy/xenial

needs-triage

jammy

DNE

noble

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/noble

needs-triage

esm-infra/bionic

needs-triage

esm-infra/focal

needs-triage

jammy

needs-triage

noble

needs-triage

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

needs-triage

jammy

DNE

noble

needs-triage

resolute

needs-triage

upstream

needs-triage

Показывать по

EPSS

Процентиль: 23%
0.003
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
4 дня назад

FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock. Authenticated clients can race AUDIN channel closure messages against DRDYNVC data parsing to trigger heap-use-after-free when accessing freed channel objects.

CVSS3: 7.5
nvd
4 дня назад

FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock. Authenticated clients can race AUDIN channel closure messages against DRDYNVC data parsing to trigger heap-use-after-free when accessing freed channel objects.

CVSS3: 7.5
debian
4 дня назад

FreeRDP server versions before 3.31.0 contain a use-after-free vulnera ...

CVSS3: 7.5
github
4 дня назад

FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock. Authenticated clients can race AUDIN channel closure messages against DRDYNVC data parsing to trigger heap-use-after-free when accessing freed channel objects.

EPSS

Процентиль: 23%
0.003
Низкий

7.5 High

CVSS3