CVE-2026-27950
published 2026-02-25CVE-2026-27950: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, the fix for the heap-use-after-free described in CVE-2026-24680 is…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.43%
35.0th percentile
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, the fix for the heap-use-after-free described in CVE-2026-24680 is incomplete. While the vulnerable execution flow referenced in the advisory exists in the SDL2 implementation, the fix appears to have been applied only to the SDL3 code path. In the SDL2 implementation, the pointer is not nulled after free. This creates a situation where the advisory suggests the vulnerability is fully resolved, while builds or environments still using SDL2 may retain the vulnerable logic. A complete fix is available in version 3.23.0.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | freerdp2 | < freerdp3 3.23.0+dfsg-1 (forky) | freerdp3 3.23.0+dfsg-1 (forky) |
| debian | freerdp3 | < freerdp3 3.23.0+dfsg-1 (forky) | freerdp3 3.23.0+dfsg-1 (forky) |
| freerdp | freerdp | < 3.23.0 | 3.23.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.05.5MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv8.7HIGH
vendor_debian8.7LOW
vendor_redhat8.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FreeRDP vulnerabilities
vendor_ubuntu·2026-03-18
CVE-2026-25954 FreeRDP vulnerabilities
Title: FreeRDP vulnerabilities
Summary: Several security issues were fixed in FreeRDP.
It was discovered that FreeRDP incorrectly handled certain RDP packets. A
remote attacker could use this issue to cause FreeRDP to crash, resulting
in a denial of service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
freerdp: FreeRDP: Denial of service due to incomplete fix for heap-use-after-free vulnerability
vendor_redhat·2026-02-25·CVSS 8.7
CVE-2026-27950 [HIGH] CWE-825 freerdp: FreeRDP: Denial of service due to incomplete fix for heap-use-after-free vulnerability
freerdp: FreeRDP: Denial of service due to incomplete fix for heap-use-after-free vulnerability
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, the fix for the heap-use-after-free described in CVE-2026-24680 is incomplete. While the vulnerable execution flow referenced in the advisory exists in the SDL2 implementation, the fix appears to have been applied only to the SDL3 code path. In the SDL2 implementation, the pointer is not nulled after free. This creates a situation where the advisory suggests the vulnerability is fully resolved, while builds or environments still using SDL2 may retain the vulnerable logic. A complete fix is available in version 3.23.0.
A flaw was found in FreeRDP. An incomplete fix for a heap-use-after-free vulnerability (
Debian
CVE-2026-27950: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio...
vendor_debian·2026·CVSS 8.7
CVE-2026-27950 [HIGH] CVE-2026-27950: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio...
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, the fix for the heap-use-after-free described in CVE-2026-24680 is incomplete. While the vulnerable execution flow referenced in the advisory exists in the SDL2 implementation, the fix appears to have been applied only to the SDL3 code path. In the SDL2 implementation, the pointer is not nulled after free. This creates a situation where the advisory suggests the vulnerability is fully resolved, while builds or environments still using SDL2 may retain the vulnerable logic. A complete fix is available in version 3.23.0.
Scope: local
bookworm: resolved
bullseye: resolved
VulDB
FreeRDP up to 3.22.x use after free (GHSA-rvfg-86cr-5r6p / Nessus ID 300174)
vuldb·2026-05-14·CVSS 5.5
CVE-2026-27950 [MEDIUM] FreeRDP up to 3.22.x use after free (GHSA-rvfg-86cr-5r6p / Nessus ID 300174)
A vulnerability identified as critical has been detected in FreeRDP up to 3.22.x. This vulnerability affects unknown code. The manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2026-27950. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
OSV
CVE-2026-27950: FreeRDP is a free implementation of the Remote Desktop Protocol
osv·2026-02-25·CVSS 8.7
CVE-2026-27950 [HIGH] CVE-2026-27950: FreeRDP is a free implementation of the Remote Desktop Protocol
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, the fix for the heap-use-after-free described in CVE-2026-24680 is incomplete. While the vulnerable execution flow referenced in the advisory exists in the SDL2 implementation, the fix appears to have been applied only to the SDL3 code path. In the SDL2 implementation, the pointer is not nulled after free. This creates a situation where the advisory suggests the vulnerability is fully resolved, while builds or environments still using SDL2 may retain the vulnerable logic. A complete fix is available in version 3.23.0.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-27950 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.7
CVE-2026-27950 [HIGH] CVE-2026-27950 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27950 :
NixOS vulnerability analysis and mitigation
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, the fix for the heap-use-after-free described in CVE-2026-24680 is incomplete. While the vulnerable execution flow referenced in the advisory exists in the SDL2 implementation, the fix appears to have been applied only to the SDL3 code path. In the SDL2 implementation, the pointer is not nulled after free. This creates a situation where the advisory suggests the vulnerability is fully resolved, while builds or environments still using SDL2 may retain the vulnerable logic. A complete fix is available in version 3.23.0.
Source : NVD
## 5.5
Score
Published February 25, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
NixO
Bugzilla
CVE-2026-27950 freerdp: FreeRDP: Denial of service due to incomplete fix for heap-use-after-free vulnerability [fedora-42]
bugzilla·2026-02-25·CVSS 5.5
CVE-2026-27950 [MEDIUM] CVE-2026-27950 freerdp: FreeRDP: Denial of service due to incomplete fix for heap-use-after-free vulnerability [fedora-42]
CVE-2026-27950 freerdp: FreeRDP: Denial of service due to incomplete fix for heap-use-after-free vulnerability [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This bug is already fixed in a published Bodhi update.
---
FEDORA-2026-53fe996a57 (freerdp-3.23.0-1.fc42) has been submitted as an update to Fedora 42.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-53fe996a57
https://github.com/FreeRDP/FreeRDP/blob/master/client/SDL/SDL2/sdl_pointer.cpp#L63-L64https://github.com/FreeRDP/FreeRDP/commit/5f62aa11c1bdf00f94c40ea9ebb260a752740b80https://github.com/FreeRDP/FreeRDP/commit/c42ecbd183b001e76bfc3614cddfad0034acc758https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-rvfg-86cr-5r6p
2026-02-25
Published