FreeRDP vulnerability

FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock. Authenticated clients can race AUDIN channel closure messages against DRDYNVC data parsing to trigger heap-use-after-free when accessing freed channel objects.

Published 15 Sep 2026Updated 16 Sep 20262 sources
CVSS 7.7

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.