CVE-2026-24678
published 2026-02-09CVE-2026-24678: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, A capture thread sends sample responses using a freed channel callback after…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.63%
46.4th percentile
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, A capture thread sends sample responses using a freed channel callback after a device channel close, leading to a use after free in ecam_channel_write. This vulnerability is fixed in 3.22.0.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | freerdp2 | < freerdp3 3.22.0+dfsg-1 (forky) | freerdp3 3.22.0+dfsg-1 (forky) |
| debian | freerdp3 | < freerdp3 3.22.0+dfsg-1 (forky) | freerdp3 3.22.0+dfsg-1 (forky) |
| freerdp | freerdp | < 3.22.0 | 3.22.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv8.7HIGH
vendor_debian8.7HIGH
vendor_redhat8.7HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
FreeRDP up to 3.21.x ecam_channel_write use after free (GHSA-6gvg-29wx-6v7h / Nessus ID 299346)
vuldb·2026-07-01·CVSS 7.5
CVE-2026-24678 [HIGH] FreeRDP up to 3.21.x ecam_channel_write use after free (GHSA-6gvg-29wx-6v7h / Nessus ID 299346)
A vulnerability labeled as critical has been found in FreeRDP up to 3.21.x. This affects the function ecam_channel_write. The manipulation results in use after free.
This vulnerability is reported as CVE-2026-24678. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
OSV
freerdp2, freerdp3 vulnerabilities
osv·2026-02-16·CVSS 6.9
CVE-2026-23948 [MEDIUM] freerdp2, freerdp3 vulnerabilities
freerdp2, freerdp3 vulnerabilities
It was discovered that FreeRDP incorrectly handled memory under certain
circumstances, which could lead to a NULL pointer dereference. An
attacker could possibly use this issue to cause a denial of service.
(CVE-2026-23948)
It was discovered that FreeRDP did not correctly validate the size of
certain variables, which could cause a buffer overflow. An attacker could
possibly use this issue to cause a denial of service or execute arbitrary
code. This issue only affected FreeRDP3 in Ubuntu 24.04 LTS and Ubuntu
25.10. (CVE-2026-24491)
It was discovered that FreeRDP did not correctly validate the size of
certain variables, which could cause a buffer overflow. An attacker could
possibly use this issue to cause a denial of service or execute arbitrary
code. (
OSV
CVE-2026-24678: FreeRDP is a free implementation of the Remote Desktop Protocol
osv·2026-02-09·CVSS 8.7
CVE-2026-24678 [HIGH] CVE-2026-24678: FreeRDP is a free implementation of the Remote Desktop Protocol
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, A capture thread sends sample responses using a freed channel callback after a device channel close, leading to a use after free in ecam_channel_write. This vulnerability is fixed in 3.22.0.
Ubuntu
FreeRDP vulnerabilities
vendor_ubuntu·2026-02-16·CVSS 7.5
CVE-2026-23948 [HIGH] FreeRDP vulnerabilities
Title: FreeRDP vulnerabilities
Summary: Several security issues were fixed in FreeRDP.
It was discovered that FreeRDP incorrectly handled memory under certain
circumstances, which could lead to a NULL pointer dereference. An
attacker could possibly use this issue to cause a denial of service.
(CVE-2026-23948)
It was discovered that FreeRDP did not correctly validate the size of
certain variables, which could cause a buffer overflow. An attacker could
possibly use this issue to cause a denial of service or execute arbitrary
code. This issue only affected FreeRDP3 in Ubuntu 24.04 LTS and Ubuntu
25.10. (CVE-2026-24491)
It was discovered that FreeRDP did not correctly validate the size of
certain variables, which could cause a buffer overflow. An attacker could
possibly use this issue to c
Red Hat
freerdp: FreeRDP: Denial of Service via use after free in ecam_channel_write
vendor_redhat·2026-02-09·CVSS 8.7
CVE-2026-24678 [HIGH] CWE-825 freerdp: FreeRDP: Denial of Service via use after free in ecam_channel_write
freerdp: FreeRDP: Denial of Service via use after free in ecam_channel_write
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, A capture thread sends sample responses using a freed channel callback after a device channel close, leading to a use after free in ecam_channel_write. This vulnerability is fixed in 3.22.0.
A denial of service flaw has been found in FreeRDP. A capture thread sends sample responses using a freed channel callback after a device channel close, leading to a use after free in ecam_channel_write.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stabilit
Debian
CVE-2026-24678: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0...
vendor_debian·2026·CVSS 8.7
CVE-2026-24678 [HIGH] CVE-2026-24678: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0...
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, A capture thread sends sample responses using a freed channel callback after a device channel close, leading to a use after free in ecam_channel_write. This vulnerability is fixed in 3.22.0.
Scope: local
bookworm: open
bullseye: open
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-24678 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.7
CVE-2026-24678 [HIGH] CVE-2026-24678 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24678 :
NixOS vulnerability analysis and mitigation
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, A capture thread sends sample responses using a freed channel callback after a device channel close, leading to a use after free in ecam_channel_write. This vulnerability is fixed in 3.22.0.
Source : NVD
## 8.7
Score
Published February 9, 2026
Severity HIGH
CNA Score 8.7
Affected Technologies
NixOS
Rocky Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
freerdp-debugsource
freerdp-server-debuginfo
Sources
NVD
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.
Bugzilla
CVE-2026-24678 freerdp: FreeRDP: Denial of Service via use after free in ecam_channel_write
bugzilla·2026-02-09·CVSS 8.7
CVE-2026-24678 [HIGH] CVE-2026-24678 freerdp: FreeRDP: Denial of Service via use after free in ecam_channel_write
CVE-2026-24678 freerdp: FreeRDP: Denial of Service via use after free in ecam_channel_write
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, A capture thread sends sample responses using a freed channel callback after a device channel close, leading to a use after free in ecam_channel_write. This vulnerability is fixed in 3.22.0.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:3068 https://access.redhat.com/errata/RHSA-2026:3068
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10.0 Extended Update Support
Via RHSA-2026:4121 https://access.redhat.com/errata/RHSA-2026:4121
---
This issue has been addressed in the following products:
Red Hat Enterpri
https://github.com/FreeRDP/FreeRDP/commit/f3ab1a16139036179d9852745fdade18fec11600https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-6gvg-29wx-6v7hhttps://access.redhat.com/errata/RHSA-2026:19033https://access.redhat.com/errata/RHSA-2026:3068https://access.redhat.com/errata/RHSA-2026:4121https://access.redhat.com/security/cve/CVE-2026-24678https://bugzilla.redhat.com/show_bug.cgi?id=2438197https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24678.json
2026-02-09
Published