Logo
vulnerabilityCVE-2026-24682
Name
CVE-2026-24682
Source
NVD ( link)Debian ( link)
Description
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, audin_server_recv_formats frees an incorrect number of audio formats on parse failure (i + i), leading to out-of-bounds access in audio_formats_free. This vulnerability is fixed in 3.22.0.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
freerdp
Exploitable

Vulnerability Ratings#


8.7
CVSSv4
7.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.11.8
Patched
buildroot
master
2.11.8
Patched
yocto
master
2.11.8
Exploitable
yocto
master
3.26.0
Not Affected
yocto
scarthgap
2.11.8
Exploitable
yocto
scarthgap
3.4.0
Patched

Resolved with patches#


freerdp (buildroot:2025.02.x)

#
Title
Author
Resolve
1
[channels,audin] fix audin_server_recv_formats cleanup
akallabeth <akallabeth@posteo.net>
CVE-2026-24682

freerdp (buildroot:master)

#
Title
Author
Resolve
1
[channels,audin] fix audin_server_recv_formats cleanup
akallabeth <akallabeth@posteo.net>
CVE-2026-24682

freerdp3 (yocto:scarthgap)

#
Title
Author
Resolve
1
[channels,audin] fix audin_server_recv_formats cleanup
akallabeth <akallabeth@posteo.net>
CVE-2026-24682