
CVE-2026-91947
FreeRDP
•
severity
published
An RDP client with an active AUDIN dynamic virtual channel can trigger a server-side heap use-after-free by racing FreeRDP's DRDYNVC parser against closure of that channel. The flaw can crash the server and may permit broader memory corruption through stale stream and queue pointers; code execution was not demonstrated.
FreeRDP is embedded by remote-desktop projects including GNOME Remote Desktop and KDE's KRdp; downstream exposure and whether the required channel state occurs before or after desktop-user authentication depend on the integration.
The lookup returns an unreferenced rdpPeerChannel pointer and unlocks the synchronized table before the parser reads the channel state or uses its receiveData stream and message queue. Concurrent channel closure removes the table entry and frees the queue, stream, lock, and channel object. AddressSanitizer deterministically reproduced the stale access on FreeRDP 3.30.0 and the tested pre-fix master revision.
The direct demonstrated impact is an attacker-triggered server abort. Shaped heap reuse could potentially turn later stream writes or queue operations into broader memory corruption. The issue is classified as CWE-416 and CWE-362. FreeRDP 2.0.0 through 3.30.0 are affected; version 3.31.0 serializes parsing against channel closure and is the first patched release.
CVE pending.
References
Explore our other findings
