Unrated severityNVD Advisory· Published Feb 25, 2026· Updated Feb 26, 2026
FreeRDP has heap-use-after-free in xf_rail_server_local_move_size
CVE-2026-25954
Description
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, xf_rail_server_local_move_size dereferences a freed xfAppWindow pointer because xf_rail_get_window returns an unprotected pointer from the railWindows hash table, and the main thread can concurrently delete the window (via a window delete order) while the RAIL channel thread is still using the pointer. Version 3.23.0 fixes the issue.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.cmitrex_refsource_MISC
- github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.cmitrex_refsource_MISC
- github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.cmitrex_refsource_MISC
- github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.cmitrex_refsource_MISC
- github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.cmitrex_refsource_MISC
- github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.cmitrex_refsource_MISC
- github.com/FreeRDP/FreeRDP/commit/1994e9844212a6dfe0ff12309fef520e888986b5mitrex_refsource_MISC
- github.com/FreeRDP/FreeRDP/security/advisories/GHSA-cc88-4j37-mw6jmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.