CVE-2026-63652: FreeRDP: Double-free of `client_formats` in the rdpsnd server channel on a malformed Client Audio Formats PDU

Published Aug 19, 2026
·
Updated

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsndserverrecvformats in channels/rdpsnd/server/rdpsndmain.c frees context->clientformats on a malformed Client Audio Formats PDU without clearing the owning pointer or numclientformats. An authenticated RDP client can trigger an error such as a cbSize larger than the remaining record, leave the dangling pointer in the server context, and cause rdpsndservercontextfree to free the same allocation again at session teardown. This reliably terminates the server and can create allocator-dependent heap corruption. This issue is fixed in version 3.28.0.

Affected Software

1 affected component
FreeRDP freerdp<3.28.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade FreeRDP to a version that resolves this vulnerability.

    Fixed in 3.28.0

Event History

Aug 19, 2026
CVE Published
via MITRE·05:59 PM
Data Sourced
via MITRE·05:59 PM
DescriptionWeakness

Frequently Asked Questions

1

Which deployments should be prioritized for remediation?

FreeRDP versions prior to 3.28.0 that operate an RDP server and process the rdpsnd server channel are affected. The issue is fixed in FreeRDP 3.28.0.

2

What access does an attacker need?

An attacker must be an authenticated RDP client. They can send a malformed Client Audio Formats PDU, such as one containing a cbSize value larger than the remaining record.

3

What is the expected impact of successful exploitation?

The double-free reliably terminates the server at session teardown. Depending on allocator behavior, it can also result in heap corruption.

4

Is a workaround available when an immediate upgrade is not possible?

The provided information identifies upgrading to version 3.28.0 as the fix. It does not describe a configuration-based workaround or other mitigation for unpatched deployments.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203