
🚨 HIGH - FreeRDP DYNVC channel race triggers heap use-after-free (CVE-2026-56297) FreeRDP clients before 3.22.0 are vulnerable to a heap use-after-free in the Dynamic Virtual Channel (drdynvc) handling path, specifically around dvcman_channel_close and dvcman_call_on_receive. The root cause is a use-after-free condition caused by improper synchronization of channel_callback access, enabling a race between close and receive handlers. An attacker can exploit this by operating a malicious RDP server and racing DYNVC_DATA and DYNVC_CLOSE messages to hit the freed callback in the drdynvc client thread, with no client-side privileges required beyond initiating an RDP connection. Successful exploitation can crash the client (denial of service) and may be leveraged for remote code execution in the context of the FreeRDP client process. 👉 Affected: FreeRDP < 3.22.0 | Upgrade to 3.22.0
Post summary
FreeRDP clients prior to v3.22.0 suffer a heap use‑after‑free via a race condition in the DYNVC channel, leading to possible denial of service or remote code execution; users should upgrade to 3.22.0.
