CVE-2026-56297: FreeRDP - Use-After-Free via Race Condition in DRDYNVC Channel Callback
FreeRDP before 3.22.0 contains a use-after-free vulnerability in dvcmanchannelclose and dvcmancallonreceive due to improper synchronization of channelcallback access. A malicious RDP server can trigger a race condition by sending DYNVCDATA and DYNVCCLOSE messages concurrently, causing heap-use-after-free in the drdynvc client thread and potentially enabling remote code execution or denial of service.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FreeRDPto a version that resolves this vulnerability.Fixed in 3.22.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56297?
CVE-2026-56297 has a high severity rating of 8.3.
How do I fix CVE-2026-56297?
To fix CVE-2026-56297, upgrade FreeRDP to version 3.22.0 or later.
What type of vulnerability is CVE-2026-56297?
CVE-2026-56297 is a use-after-free vulnerability caused by a race condition.
What can attackers exploit in CVE-2026-56297?
Attackers can exploit CVE-2026-56297 by sending DYNVC_DATA and DYNVC_CLOSE messages simultaneously from a malicious RDP server.
Which software is affected by CVE-2026-56297?
CVE-2026-56297 affects FreeRDP versions prior to 3.22.0.