VYPR
High severity7.0OSV Advisory· Published Jul 8, 2026· Updated Jul 10, 2026

CVE-2026-56297

CVE-2026-56297

Description

FreeRDP before 3.22.0 contains a use-after-free vulnerability in dvcman_channel_close and dvcman_call_on_receive due to improper synchronization of channel_callback access. A malicious RDP server can trigger a race condition by sending DYNVC_DATA and DYNVC_CLOSE messages concurrently, causing heap-use-after-free in the drdynvc client thread and potentially enabling remote code execution or denial of service.

Affected products

3
  • Range: 3.5.1, 3.5.0, 3.4.0, …
  • Freerdp/Freerdp2 versions
    cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*range: <3.22.0
    • (no CPE)range: <3.22.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.