CVE-2026-23884
published 2026-01-19CVE-2026-23884: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, offscreen bitmap deletion leaves `gdi->drawing` pointing to freed…
PriorityP356critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.40%
32.8th percentile
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, offscreen bitmap deletion leaves `gdi->drawing` pointing to freed memory, causing UAF when related update packets arrive. A malicious server can trigger a client‑side use after free, causing a crash (DoS) and potential heap corruption with code‑execution risk depending on allocator behavior and surrounding heap layout. Version 3.21.0 contains a patch for the issue.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | freerdp2 | < freerdp3 3.21.0+dfsg-1 (forky) | freerdp3 3.21.0+dfsg-1 (forky) |
| debian | freerdp3 | < freerdp3 3.21.0+dfsg-1 (forky) | freerdp3 3.21.0+dfsg-1 (forky) |
| freerdp | freerdp | < 3.21.0 | 3.21.0 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.07.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv7.7HIGH
vendor_debian7.7HIGH
vendor_redhat7.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
FreeRDP up to 3.20.x use after free (EUVD-2026-3310 / Nessus ID 297418)
vuldb·2026-06-11·CVSS 9.8
CVE-2026-23884 [CRITICAL] FreeRDP up to 3.20.x use after free (EUVD-2026-3310 / Nessus ID 297418)
A vulnerability was found in FreeRDP up to 3.20.x. It has been declared as critical. Affected is an unknown function. The manipulation results in use after free.
This vulnerability is reported as CVE-2026-23884. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
OSV
CVE-2026-23884: FreeRDP is a free implementation of the Remote Desktop Protocol
osv·2026-01-19·CVSS 7.7
CVE-2026-23884 [HIGH] CVE-2026-23884: FreeRDP is a free implementation of the Remote Desktop Protocol
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, offscreen bitmap deletion leaves `gdi->drawing` pointing to freed memory, causing UAF when related update packets arrive. A malicious server can trigger a client‑side use after free, causing a crash (DoS) and potential heap corruption with code‑execution risk depending on allocator behavior and surrounding heap layout. Version 3.21.0 contains a patch for the issue.
Ubuntu
FreeRDP vulnerabilities
vendor_ubuntu·2026-03-18
CVE-2026-25954 FreeRDP vulnerabilities
Title: FreeRDP vulnerabilities
Summary: Several security issues were fixed in FreeRDP.
It was discovered that FreeRDP incorrectly handled certain RDP packets. A
remote attacker could use this issue to cause FreeRDP to crash, resulting
in a denial of service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
freerdp: FreeRDP: Denial of Service and potential code execution via use-after-free vulnerability
vendor_redhat·2026-01-19·CVSS 7.7
CVE-2026-23884 [HIGH] CWE-416 freerdp: FreeRDP: Denial of Service and potential code execution via use-after-free vulnerability
freerdp: FreeRDP: Denial of Service and potential code execution via use-after-free vulnerability
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, offscreen bitmap deletion leaves `gdi->drawing` pointing to freed memory, causing UAF when related update packets arrive. A malicious server can trigger a client‑side use after free, causing a crash (DoS) and potential heap corruption with code‑execution risk depending on allocator behavior and surrounding heap layout. Version 3.21.0 contains a patch for the issue.
A flaw was found in FreeRDP, a free implementation of the Remote Desktop Protocol. A malicious server can exploit this vulnerability when a client connects to it. Specifically, offscreen bitmap deletion can lead to a use-after-free (UAF) cond
Debian
CVE-2026-23884: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio...
vendor_debian·2026·CVSS 7.7
CVE-2026-23884 [HIGH] CVE-2026-23884: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio...
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, offscreen bitmap deletion leaves `gdi->drawing` pointing to freed memory, causing UAF when related update packets arrive. A malicious server can trigger a client‑side use after free, causing a crash (DoS) and potential heap corruption with code‑execution risk depending on allocator behavior and surrounding heap layout. Version 3.21.0 contains a patch for the issue.
Scope: local
bookworm: open
bullseye: open
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-23884 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.7
CVE-2026-23884 [HIGH] CVE-2026-23884 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23884 :
NixOS vulnerability analysis and mitigation
gdi->drawing
Source : NVD
## 7.7
Score
Published January 19, 2026
Severity HIGH
CNA Score 7.7
Affected Technologies
NixOS
Rocky Linux
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 39.2
Exploitation Probability (EPSS) 0.2
Affected packages and libraries
freerdp-debugsource
freerdp2
Sources
NVD
AlmaLinux 8 Severity HIGH Has Fix Added at: Feb 08, 2026
AlmaLinux 9 Severity HIGH Has Fix Added at: Feb 11, 2026
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.21, 3.22, 3.23 Severity CRITICAL Has Fix Added at: Jan 29, 2026
Alpine edge Severity CRITICAL Has Fix Added at: Jan 26, 2026
Chaingu
Bugzilla
CVE-2026-23884 freerdp: FreeRDP: Denial of Service and potential code execution via use-after-free vulnerability
bugzilla·2026-01-19·CVSS 7.7
CVE-2026-23884 [HIGH] CVE-2026-23884 freerdp: FreeRDP: Denial of Service and potential code execution via use-after-free vulnerability
CVE-2026-23884 freerdp: FreeRDP: Denial of Service and potential code execution via use-after-free vulnerability
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, offscreen bitmap deletion leaves `gdi->drawing` pointing to freed memory, causing UAF when related update packets arrive. A malicious server can trigger a client‑side use after free, causing a crash (DoS) and potential heap corruption with code‑execution risk depending on allocator behavior and surrounding heap layout. Version 3.21.0 contains a patch for the issue.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:2048 https://access.redhat.com/errata/RHSA-2026:2048
---
This issue has been addressed in the following products
Bugzilla
CVE-2026-23884 freerdp2: FreeRDP: Denial of Service and potential code execution via use-after-free vulnerability [fedora-42]
bugzilla·2026-01-19·CVSS 7.7
CVE-2026-23884 [HIGH] CVE-2026-23884 freerdp2: FreeRDP: Denial of Service and potential code execution via use-after-free vulnerability [fedora-42]
CVE-2026-23884 freerdp2: FreeRDP: Denial of Service and potential code execution via use-after-free vulnerability [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '42'.
Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a c
https://github.com/FreeRDP/FreeRDP/blob/3370e30e92a021eb680892dda14d642bc8b8727c/libfreerdp/cache/offscreen.c#L114-L122https://github.com/FreeRDP/FreeRDP/blob/3370e30e92a021eb680892dda14d642bc8b8727c/libfreerdp/cache/offscreen.c#L87-L91https://github.com/FreeRDP/FreeRDP/releases/tag/3.21.0https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-cfgj-vc84-f3pphttps://access.redhat.com/errata/RHSA-2026:2048https://access.redhat.com/errata/RHSA-2026:2081https://access.redhat.com/errata/RHSA-2026:2222https://access.redhat.com/errata/RHSA-2026:2714https://access.redhat.com/errata/RHSA-2026:2736https://access.redhat.com/errata/RHSA-2026:2770https://access.redhat.com/errata/RHSA-2026:2824https://access.redhat.com/errata/RHSA-2026:2952https://access.redhat.com/errata/RHSA-2026:3036https://access.redhat.com/errata/RHSA-2026:3037https://access.redhat.com/errata/RHSA-2026:3038https://access.redhat.com/errata/RHSA-2026:3039https://access.redhat.com/errata/RHSA-2026:3041https://access.redhat.com/security/cve/CVE-2026-23884https://bugzilla.redhat.com/show_bug.cgi?id=2430880https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23884.json
2026-01-19
Published