Количество 25
Количество 25
BDU:2026-04146
Уязвимость функций xf_SetWindowMinMaxInfo(), xf_rail_get_window() RDP-клиента FreeRDP , позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
ROS-20260615-73-0026
Уязвимость freerdp3
ROS-20260615-73-0025
Уязвимость freerdp
CVE-2026-25952
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_SetWindowMinMaxInfo` dereferences a freed `xfAppWindow` pointer because `xf_rail_get_window` in `xf_rail_server_min_max_info` returns an unprotected pointer from the `railWindows` hash table, and the main thread can concurrently delete the window (via a window delete order) while the RAIL channel thread is still using the pointer. Version 3.23.0 fixes the issue.
CVE-2026-25952
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_SetWindowMinMaxInfo` dereferences a freed `xfAppWindow` pointer because `xf_rail_get_window` in `xf_rail_server_min_max_info` returns an unprotected pointer from the `railWindows` hash table, and the main thread can concurrently delete the window (via a window delete order) while the RAIL channel thread is still using the pointer. Version 3.23.0 fixes the issue.
CVE-2026-25952
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_SetWindowMinMaxInfo` dereferences a freed `xfAppWindow` pointer because `xf_rail_get_window` in `xf_rail_server_min_max_info` returns an unprotected pointer from the `railWindows` hash table, and the main thread can concurrently delete the window (via a window delete order) while the RAIL channel thread is still using the pointer. Version 3.23.0 fixes the issue.
CVE-2026-25952
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...
RLSA-2026:19358
Moderate: freerdp security update
RLSA-2026:16482
Moderate: freerdp security update
RLSA-2026:16019
Moderate: freerdp security update
ELSA-2026-20546
ELSA-2026-20546: freerdp security update (MODERATE)
ELSA-2026-19358
ELSA-2026-19358: freerdp security update (MODERATE)
ELSA-2026-16482
ELSA-2026-16482: freerdp security update (MODERATE)
ELSA-2026-16019
ELSA-2026-16019: freerdp security update (MODERATE)
RLSA-2026:19142
Moderate: freerdp security update
RLSA-2026:16014
Moderate: freerdp security update
ELSA-2026-19142
ELSA-2026-19142: freerdp security update (MODERATE)
ELSA-2026-16014
ELSA-2026-16014: freerdp security update (MODERATE)
SUSE-SU-2026:1635-1
Security update for freerdp
SUSE-SU-2026:1634-1
Security update for freerdp
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-04146 Уязвимость функций xf_SetWindowMinMaxInfo(), xf_rail_get_window() RDP-клиента FreeRDP , позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации | CVSS3: 9.8 | 1% Низкий | 5 месяцев назад | |
ROS-20260615-73-0026 Уязвимость freerdp3 | CVSS3: 9.8 | 1% Низкий | около 2 месяцев назад | |
ROS-20260615-73-0025 Уязвимость freerdp | CVSS3: 9.8 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-25952 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_SetWindowMinMaxInfo` dereferences a freed `xfAppWindow` pointer because `xf_rail_get_window` in `xf_rail_server_min_max_info` returns an unprotected pointer from the `railWindows` hash table, and the main thread can concurrently delete the window (via a window delete order) while the RAIL channel thread is still using the pointer. Version 3.23.0 fixes the issue. | CVSS3: 9.8 | 1% Низкий | 5 месяцев назад | |
CVE-2026-25952 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_SetWindowMinMaxInfo` dereferences a freed `xfAppWindow` pointer because `xf_rail_get_window` in `xf_rail_server_min_max_info` returns an unprotected pointer from the `railWindows` hash table, and the main thread can concurrently delete the window (via a window delete order) while the RAIL channel thread is still using the pointer. Version 3.23.0 fixes the issue. | CVSS3: 6.4 | 1% Низкий | 5 месяцев назад | |
CVE-2026-25952 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_SetWindowMinMaxInfo` dereferences a freed `xfAppWindow` pointer because `xf_rail_get_window` in `xf_rail_server_min_max_info` returns an unprotected pointer from the `railWindows` hash table, and the main thread can concurrently delete the window (via a window delete order) while the RAIL channel thread is still using the pointer. Version 3.23.0 fixes the issue. | CVSS3: 9.8 | 1% Низкий | 5 месяцев назад | |
CVE-2026-25952 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ... | CVSS3: 9.8 | 1% Низкий | 5 месяцев назад | |
RLSA-2026:19358 Moderate: freerdp security update | 2 месяца назад | |||
RLSA-2026:16482 Moderate: freerdp security update | 3 месяца назад | |||
RLSA-2026:16019 Moderate: freerdp security update | 3 месяца назад | |||
ELSA-2026-20546 ELSA-2026-20546: freerdp security update (MODERATE) | около 1 месяца назад | |||
ELSA-2026-19358 ELSA-2026-19358: freerdp security update (MODERATE) | около 1 месяца назад | |||
ELSA-2026-16482 ELSA-2026-16482: freerdp security update (MODERATE) | 3 месяца назад | |||
ELSA-2026-16019 ELSA-2026-16019: freerdp security update (MODERATE) | 3 месяца назад | |||
RLSA-2026:19142 Moderate: freerdp security update | 2 месяца назад | |||
RLSA-2026:16014 Moderate: freerdp security update | 3 месяца назад | |||
ELSA-2026-19142 ELSA-2026-19142: freerdp security update (MODERATE) | 11 дней назад | |||
ELSA-2026-16014 ELSA-2026-16014: freerdp security update (MODERATE) | 3 месяца назад | |||
SUSE-SU-2026:1635-1 Security update for freerdp | 3 месяца назад | |||
SUSE-SU-2026:1634-1 Security update for freerdp | 3 месяца назад |
Уязвимостей на страницу