Description
FreeRDP before 3.22.0 contains a use-after-free vulnerability in dvcman_channel_close and dvcman_call_on_receive due to improper synchronization of channel_callback access. A malicious RDP server can trigger a race condition by sending DYNVC_DATA and DYNVC_CLOSE messages concurrently, causing heap-use-after-free in the drdynvc client thread and potentially enabling remote code execution or denial of service.
Severity (CVSS)
| Base score | 8.3 |
|---|---|
| Severity | High |
| Version | CVSS 4.0 |
| Vector | CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N |
| Provided by | CNA |
Weaknesses
- CWE-362 — Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Affected products
| Vendor | Product | Versions |
|---|---|---|
| FreeRDP | FreeRDP | 0 to <3.22.0; 3.22.0 |
References
Generated from the official CVE List on 09 Jul 2026 07:08 UTC.