Logo
vulnerabilityCVE-2026-64621
Name
CVE-2026-64621
Source
NVD ( link)Debian ( link)
Description
FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double-free vulnerability in freerdp_client_rdp_file_apply_to_settings() (client/common/file.c) when parsing the selectedmonitors field of a .rdp connection file. The MonitorIds array is allocated through the settings object, and a raw non-owning pointer to it is freed on the strtoul error path without clearing settings->MonitorIds, leaving it dangling; at teardown freerdp_settings_free() frees the same buffer again. An attacker who convinces a victim to open a crafted .rdp file with oversized monitor tokens can trigger a size-controlled double-free in any FreeRDP CLI client (xfreerdp/sdl-freerdp/wlfreerdp) in the default configuration.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
freerdp3
Exploitable

Vulnerability Ratings#


9.3
CVSSv4
7.3
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.11.8
Not Affected
buildroot
master
2.11.8
Not Affected
yocto
kirkstone
2.6.1
Not Affected
yocto
master
2.11.8
Not Affected
yocto
master
3.30.0
Not Affected