CVE-2026-24684
published 2026-02-09CVE-2026-24684: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, the RDPSND async playback thread can process queued PDUs after the channel is…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.53%
41.5th percentile
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, the RDPSND async playback thread can process queued PDUs after the channel is closed and internal state is freed, leading to a use after free in rdpsnd_treat_wave. This vulnerability is fixed in 3.22.0.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | freerdp2 | < freerdp3 3.22.0+dfsg-1 (forky) | freerdp3 3.22.0+dfsg-1 (forky) |
| debian | freerdp3 | < freerdp3 3.22.0+dfsg-1 (forky) | freerdp3 3.22.0+dfsg-1 (forky) |
| freerdp | freerdp | < 3.22.0 | 3.22.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv8.7HIGH
vendor_debian8.7HIGH
vendor_redhat8.7HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FreeRDP vulnerabilities
vendor_ubuntu·2026-02-16·CVSS 7.5
CVE-2026-23948 [HIGH] FreeRDP vulnerabilities
Title: FreeRDP vulnerabilities
Summary: Several security issues were fixed in FreeRDP.
It was discovered that FreeRDP incorrectly handled memory under certain
circumstances, which could lead to a NULL pointer dereference. An
attacker could possibly use this issue to cause a denial of service.
(CVE-2026-23948)
It was discovered that FreeRDP did not correctly validate the size of
certain variables, which could cause a buffer overflow. An attacker could
possibly use this issue to cause a denial of service or execute arbitrary
code. This issue only affected FreeRDP3 in Ubuntu 24.04 LTS and Ubuntu
25.10. (CVE-2026-24491)
It was discovered that FreeRDP did not correctly validate the size of
certain variables, which could cause a buffer overflow. An attacker could
possibly use this issue to c
Red Hat
freerdp: FreeRDP has a Heap-use-after-free in play_thread
vendor_redhat·2026-02-09·CVSS 8.7
CVE-2026-24684 [HIGH] CWE-131 freerdp: FreeRDP has a Heap-use-after-free in play_thread
freerdp: FreeRDP has a Heap-use-after-free in play_thread
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, the RDPSND async playback thread can process queued PDUs after the channel is closed and internal state is freed, leading to a use after free in rdpsnd_treat_wave. This vulnerability is fixed in 3.22.0.
A heap use after free has been discovered in FreeRDP. The RDPSND async playback thread can process queued PDUs after the channel is closed and internal state is freed, leading to a use after free in rdpsnd_treat_wave.
Statement: Availability impact is limited to the FreeRDP instance on Red Hat Products. General system availability is not at risk.
Mitigation: Mitigation for this issue is either not available or the currently available options do not
Debian
CVE-2026-24684: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0...
vendor_debian·2026·CVSS 8.7
CVE-2026-24684 [HIGH] CVE-2026-24684: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0...
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, the RDPSND async playback thread can process queued PDUs after the channel is closed and internal state is freed, leading to a use after free in rdpsnd_treat_wave. This vulnerability is fixed in 3.22.0.
Scope: local
bookworm: open
bullseye: open
VulDB
FreeRDP up to 3.21.x rdpsnd_treat_wave use after free (GHSA-vcgv-xgjp-h83q / Nessus ID 299346)
vuldb·2026-06-10·CVSS 7.5
CVE-2026-24684 [HIGH] FreeRDP up to 3.21.x rdpsnd_treat_wave use after free (GHSA-vcgv-xgjp-h83q / Nessus ID 299346)
A vulnerability has been found in FreeRDP up to 3.21.x and classified as critical. This issue affects the function rdpsnd_treat_wave. This manipulation causes use after free.
The identification of this vulnerability is CVE-2026-24684. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
OSV
freerdp2, freerdp3 vulnerabilities
osv·2026-02-16·CVSS 6.9
CVE-2026-23948 [MEDIUM] freerdp2, freerdp3 vulnerabilities
freerdp2, freerdp3 vulnerabilities
It was discovered that FreeRDP incorrectly handled memory under certain
circumstances, which could lead to a NULL pointer dereference. An
attacker could possibly use this issue to cause a denial of service.
(CVE-2026-23948)
It was discovered that FreeRDP did not correctly validate the size of
certain variables, which could cause a buffer overflow. An attacker could
possibly use this issue to cause a denial of service or execute arbitrary
code. This issue only affected FreeRDP3 in Ubuntu 24.04 LTS and Ubuntu
25.10. (CVE-2026-24491)
It was discovered that FreeRDP did not correctly validate the size of
certain variables, which could cause a buffer overflow. An attacker could
possibly use this issue to cause a denial of service or execute arbitrary
code. (
OSV
CVE-2026-24684: FreeRDP is a free implementation of the Remote Desktop Protocol
osv·2026-02-09·CVSS 8.7
CVE-2026-24684 [HIGH] CVE-2026-24684: FreeRDP is a free implementation of the Remote Desktop Protocol
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, the RDPSND async playback thread can process queued PDUs after the channel is closed and internal state is freed, leading to a use after free in rdpsnd_treat_wave. This vulnerability is fixed in 3.22.0.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-24684 freerdp2: FreeRDP has a Heap-use-after-free in play_thread [fedora-42]
bugzilla·2026-02-09·CVSS 8.7
CVE-2026-24684 [HIGH] CVE-2026-24684 freerdp2: FreeRDP has a Heap-use-after-free in play_thread [fedora-42]
CVE-2026-24684 freerdp2: FreeRDP has a Heap-use-after-free in play_thread [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '42'.
Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, change the
Bugzilla
CVE-2026-24684 freerdp: FreeRDP has a Heap-use-after-free in play_thread
bugzilla·2026-02-09·CVSS 8.7
CVE-2026-24684 [HIGH] CVE-2026-24684 freerdp: FreeRDP has a Heap-use-after-free in play_thread
CVE-2026-24684 freerdp: FreeRDP has a Heap-use-after-free in play_thread
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, the RDPSND async playback thread can process queued PDUs after the channel is closed and internal state is freed, leading to a use after free in rdpsnd_treat_wave. This vulnerability is fixed in 3.22.0.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:6340 https://access.redhat.com/errata/RHSA-2026:6340
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.6 Extended Update Support
Via RHSA-2026:6727 https://access.redhat.com/errata/RHSA-2026:6727
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux
Wiz
CVE-2026-24684 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.7
CVE-2026-24684 [HIGH] CVE-2026-24684 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24684 :
NixOS vulnerability analysis and mitigation
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, the RDPSND async playback thread can process queued PDUs after the channel is closed and internal state is freed, leading to a use after free in rdpsnd_treat_wave. This vulnerability is fixed in 3.22.0.
Source : NVD
## 8.7
Score
Published February 9, 2026
Severity HIGH
CNA Score 8.7
Affected Technologies
NixOS
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libuwac0-0
freerdp-server-debuginfo
Sources
NVD
AlmaLinux 9 Severity HIGH Has Fix Added at: Apr 0
2026-02-09
Published