Name
CVE-2026-24680
Description
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, sdl_Pointer_New frees data on failure, then pointer_free calls sdl_Pointer_Free and frees it again, triggering ASan UAF. This vulnerability is fixed in 3.22.0.
CWEs
Published Date
Updated Date
Workaround
-
Analysis#
Vulnerability Ratings#
8.7
CVSSv4
7.5
CVSSv31
NaN
other
Others affected components#
Resolved with patches#
freerdp3 (yocto:scarthgap)
#
Title
Author
Resolve
1
[client,sdl] reset pointer after memory release
akallabeth <akallabeth@posteo.net>
CVE-2026-24680
CVE-2026-27950