High severity7.0OSV Advisory· Published Jul 8, 2026· Updated Jul 10, 2026
CVE-2026-56297
CVE-2026-56297
Description
FreeRDP before 3.22.0 contains a use-after-free vulnerability in dvcman_channel_close and dvcman_call_on_receive due to improper synchronization of channel_callback access. A malicious RDP server can trigger a race condition by sending DYNVC_DATA and DYNVC_CLOSE messages concurrently, causing heap-use-after-free in the drdynvc client thread and potentially enabling remote code execution or denial of service.
Affected products
3Patches
Vulnerability mechanics
References
2- github.com/FreeRDP/FreeRDP/security/advisories/GHSA-3mv2-5q57-2v8hnvdExploitVendor Advisory
- www.vulncheck.com/advisories/freerdp-use-after-free-via-race-condition-in-drdynvc-channel-callbacknvdThird Party Advisory
News mentions
0No linked articles in our index yet.