Logo
vulnerabilityCVE-2026-24684
Name
CVE-2026-24684
Source
NVD ( link)Debian ( link)
Description
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, the RDPSND async playback thread can process queued PDUs after the channel is closed and internal state is freed, leading to a use after free in rdpsnd_treat_wave. This vulnerability is fixed in 3.22.0.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
freerdp
Patched

Vulnerability Ratings#


8.7
CVSSv4
7.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.11.8
Patched
yocto
kirkstone
2.6.1
Exploitable
yocto
master
2.11.8
Exploitable
yocto
master
3.26.0
Not Affected
yocto
scarthgap
2.11.8
Exploitable
yocto
scarthgap
3.4.0
Exploitable

Resolved with patches#


freerdp (buildroot:2025.02.x)

#
Title
Author
Resolve
1
[channels,rdpsnd] terminate thread before free
akallabeth <akallabeth@posteo.net>
CVE-2026-24684
2
[channel,rdpsnd] only clean up thread before free
akallabeth <akallabeth@posteo.net>
CVE-2026-24684

freerdp (buildroot:master)

#
Title
Author
Resolve
1
[channels,rdpsnd] terminate thread before free
akallabeth <akallabeth@posteo.net>
CVE-2026-24684
2
[channel,rdpsnd] only clean up thread before free
akallabeth <akallabeth@posteo.net>
CVE-2026-24684