CVE-2026-22857
published 2026-01-14CVE-2026-22857: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap use-after-free occurs in irp_thread_func because the IRP is freed by…
PriorityP348critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.45%
36.5th percentile
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap use-after-free occurs in irp_thread_func because the IRP is freed by irp->Complete() and then accessed again on the error path. This vulnerability is fixed in 3.20.1.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | freerdp2 | < freerdp3 3.20.2+dfsg-1 (forky) | freerdp3 3.20.2+dfsg-1 (forky) |
| debian | freerdp3 | < freerdp3 3.20.2+dfsg-1 (forky) | freerdp3 3.20.2+dfsg-1 (forky) |
| freerdp | freerdp | < 3.20.1 | 3.20.1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.06.8MEDIUMCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
FreeRDP up to 3.20.0 Complete use after free (GHSA-4gxq-jhq6-4cr8 / EUVD-2026-2670)
vuldb·2026-06-11·CVSS 9.8
CVE-2026-22857 [CRITICAL] FreeRDP up to 3.20.0 Complete use after free (GHSA-4gxq-jhq6-4cr8 / EUVD-2026-2670)
A vulnerability classified as critical has been found in FreeRDP up to 3.20.0. Impacted is the function Complete. This manipulation causes use after free.
This vulnerability is tracked as CVE-2026-22857. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
OSV
CVE-2026-22857: FreeRDP is a free implementation of the Remote Desktop Protocol
osv·2026-01-14·CVSS 6.8
CVE-2026-22857 [MEDIUM] CVE-2026-22857: FreeRDP is a free implementation of the Remote Desktop Protocol
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap use-after-free occurs in irp_thread_func because the IRP is freed by irp->Complete() and then accessed again on the error path. This vulnerability is fixed in 3.20.1.
Ubuntu
FreeRDP vulnerabilities
vendor_ubuntu·2026-03-18
CVE-2026-25954 FreeRDP vulnerabilities
Title: FreeRDP vulnerabilities
Summary: Several security issues were fixed in FreeRDP.
It was discovered that FreeRDP incorrectly handled certain RDP packets. A
remote attacker could use this issue to cause FreeRDP to crash, resulting
in a denial of service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
freerdp: FreeRDP heap-use-after-free
vendor_redhat·2026-01-14·CVSS 6.8
CVE-2026-22857 [MEDIUM] CWE-416 freerdp: FreeRDP heap-use-after-free
freerdp: FreeRDP heap-use-after-free
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap use-after-free occurs in irp_thread_func because the IRP is freed by irp->Complete() and then accessed again on the error path. This vulnerability is fixed in 3.20.1.
A heap use after free flaw has been discovered in FreeRDP. This heap use-after-free occurs in `irp_thread_func` because the IRP is freed by irp->Complete() and then accessed again on the error path.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: freerdp (Red Hat Enterprise Linux 10) - Affected
Debian
CVE-2026-22857: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1...
vendor_debian·2026·CVSS 6.8
CVE-2026-22857 [MEDIUM] CVE-2026-22857: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1...
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap use-after-free occurs in irp_thread_func because the IRP is freed by irp->Complete() and then accessed again on the error path. This vulnerability is fixed in 3.20.1.
Scope: local
bookworm: open
bullseye: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-22857 freerdp: FreeRDP heap-use-after-free
bugzilla·2026-01-14·CVSS 9.8
CVE-2026-22857 [CRITICAL] CVE-2026-22857 freerdp: FreeRDP heap-use-after-free
CVE-2026-22857 freerdp: FreeRDP heap-use-after-free
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap use-after-free occurs in irp_thread_func because the IRP is freed by irp->Complete() and then accessed again on the error path. This vulnerability is fixed in 3.20.1.
Wiz
CVE-2026-22857 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.8
CVE-2026-22857 [MEDIUM] CVE-2026-22857 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-22857 :
NixOS vulnerability analysis and mitigation
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap use-after-free occurs in irp_thread_func because the IRP is freed by irp->Complete() and then accessed again on the error path. This vulnerability is fixed in 3.20.1.
Source : NVD
## 6.8
Score
Published January 14, 2026
Severity MEDIUM
CNA Score 6.8
Affected Technologies
NixOS
Wolfi
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 24.8
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
libfreerdp2
freerdp2
Sources
NVD
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.21 Severity CRITICA
2026-01-14
Published