CVE-2026-56297: high-severity vulnerability in FreeRDP
FreeRDP - Use-After-Free via Race Condition in DRDYNVC Channel Callback
Published
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.3epss 0.5%
exploitation probability
0.5%top 62% of all CVEs
observed exploitation
nono source reports it
FreeRDP before 3.22.0 contains a use-after-free vulnerability in dvcman_channel_close and dvcman_call_on_receive due to improper synchronization of channel_callback access. A malicious RDP server can trigger a race condition by sending DYNVC_DATA and DYNVC_CLOSE messages concurrently, causing heap-use-after-free in the drdynvc client thread and potentially enabling remote code execution or denial of service.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
Affected products
FreeRDP · FreeRDPRelated CVEs — FreeRDP
In the same product, most dangerous first.
CVE-2024-32459CRITICALFreeRDP Out-Of-Bounds Read in ncrush_decompressEPSS 3.7%CVE-2022-24882CRITICALServer side NTLM does not properly check parameters in FreeRDPEPSS 2.8%CVE-2020-11019MEDIUMOut of bound read in update_recv in FreeRDPEPSS 2.5%CVE-2022-24883HIGHFreeRDP Server authentication might allow invalid credentials to passEPSS 2.3%CVE-2024-32039CRITICALFreeRDP Integer overflow & OutOfBound Write in clear_decompress_residual_dataEPSS 2.3%CVE-2020-11099LOWOOB Read in license_read_new_or_upgrade_license_packet in FreeRDPEPSS 2.1%