CVE-2026-56297Patch(freerdp / freerdp)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch freerdp freerdp systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

FreeRDP before 3.22.0 contains a use-after-free vulnerability in dvcman_channel_close and dvcman_call_on_receive due to improper synchronization of channel_callback access. A malicious RDP server can trigger a race condition by sending DYNVC_DATA and DYNVC_CLOSE messages concurrently, causing heap-use-after-free in the drdynvc client thread and potentially enabling remote code execution or denial of service.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-362

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freerdp

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
freerdp

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-08: 1Patch / Workaround · 2026-07-08: 1Technical Details · 2026-07-08: 107-08
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 HIGH - FreeRDP DYNVC channel race triggers heap use-after-free (CVE-2026-56297) FreeRDP clients before 3.22.0 are vulnerable to a heap use-after-free in the Dynamic Virtual Channel (drdynvc) handling path, specifically around dvcman_channel_close and dvcman_call_on_receive. The root cause is a use-after-free condition caused by improper synchronization of channel_callback access, enabling a race between close and receive handlers. An attacker can exploit this by operating a malicious RDP server and racing DYNVC_DATA and DYNVC_CLOSE messages to hit the freed callback in the drdynvc client thread, with no client-side privileges required beyond initiating an RDP connection. Successful exploitation can crash the client (denial of service) and may be leveraged for remote code execution in the context of the FreeRDP client process. 👉 Affected: FreeRDP < 3.22.0 | Upgrade to 3.22.0

    Post summary

    FreeRDP clients prior to v3.22.0 suffer a heap use‑after‑free via a race condition in the DYNVC channel, leading to possible denial of service or remote code execution; users should upgrade to 3.22.0.

    00000101
    246 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfreerdpfreerdp---

Explore more