Vulnerability Description
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, the RDPSND async playback thread can process queued PDUs after the channel is closed and internal state is freed, leading to a use after free in rdpsnd_treat_wave. This vulnerability is fixed in 3.22.0.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Freerdp | Freerdp | < 3.22.0 |
Related Weaknesses (CWE)
References
- https://github.com/FreeRDP/FreeRDP/commit/622bb7b4402491ca003f47472d0e4781326736Patch
- https://github.com/FreeRDP/FreeRDP/commit/afa6851dc80835d3101e40fcef51b6c5c0f43ePatch
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-vcgv-xgjp-h83qPatchVendor Advisory
FAQ
What is CVE-2026-24684?
CVE-2026-24684 is a vulnerability with a CVSS score of 7.5 (HIGH). FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, the RDPSND async playback thread can process queued PDUs after the channel is closed and internal state is freed, lead...
How severe is CVE-2026-24684?
CVE-2026-24684 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-24684?
Check the references section above for vendor advisories and patch information. Affected products include: Freerdp Freerdp.