CNNVD-202602-1313 Information

CNNVD ID

CNNVD-202602-1313

CVE-2026-24684

  • CNNVD Published: 2026-02-09

Description (Chinese)

FreeRDP是FreeRDP团队的一款开源的远程桌面协议(RDP)的实现。 FreeRDP 3.22.0之前版本存在资源管理错误漏洞,该漏洞源于RDPSND异步播放线程可在通道关闭且内部状态释放后处理排队的PDU,可能导致释放后重用。

Description (English)

FreeRDP is an open-source remote desktop protocol (RDP) for the FreeRDP team. FreeRDP 3.22.0 has a resource management error loophole that originates from a PDU where the RDPSND step-by-step playway can be closed and released internally, which may lead to reuse after release.

Vulnerability Type

资源管理错误

Affected Vendor

FreeRDP

Published

2026-02-09

Last Modified

2026-02-24

References

https://github.com/FreeRDP/FreeRDP/commit/622bb7b4402491ca003f47472d0e478132673696 https://github.com/FreeRDP/FreeRDP/commit/afa6851dc80835d3101e40fcef51b6c5c0f43ea5 https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-vcgv-xgjp-h83q

Patch

https://github.com/FreeRDP/FreeRDP/releases

Share on: