CVE-2026-24679: FreeRDP has a heap-buffer-overflow in urb_select_interface
Published Feb 9, 2026
·Updated
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, The URBDRC client uses server-supplied interface numbers as array indices without bounds checks, causing an out-of-bounds read in libusbudevselectinterface. This vulnerability is fixed in 3.22.0.
Affected Software
2 affected components
FreeRDP freerdp<3.22.0
FreeRDP freerdp<3.22.0
Remediation
Event History
Feb 9, 2026
CVE Published
via MITRE·06:19 PM
Data Sourced
via MITRE·06:19 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Data Sourced
via Red Hat·08:02 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-24679?
CVE-2026-24679 is classified as a high severity vulnerability due to the potential for heap buffer overflow.
2
How do I fix CVE-2026-24679?
To fix CVE-2026-24679, upgrade FreeRDP to version 3.22.0 or later.
3
What does CVE-2026-24679 affect?
CVE-2026-24679 affects FreeRDP versions prior to 3.22.0.
4
What is the nature of the vulnerability in CVE-2026-24679?
CVE-2026-24679 involves a heap-buffer-overflow caused by improper bounds checking of server-supplied interface numbers.
5
Is CVE-2026-24679 exploitable remotely?
Yes, CVE-2026-24679 can potentially be exploited remotely due to its nature in the Remote Desktop Protocol implementation.