REDHAT-BUG-2519822: Medium severity FreeRDP freerdp vulnerability

Published Aug 19, 2026
·
Updated

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsndserverrecvformats in channels/rdpsnd/server/rdpsndmain.c frees context->clientformats on a malformed Client Audio Formats PDU without clearing the owning pointer or numclientformats. An authenticated RDP client can trigger an error such as a cbSize larger than the remaining record, leave the dangling pointer in the server context, and cause rdpsndservercontextfree to free the same allocation again at session teardown. This reliably terminates the server and can create allocator-dependent heap corruption. This issue is fixed in version 3.28.0.

Affected Software

1 affected component
FreeRDP freerdp<3.28.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade FreeRDP to a version that resolves this vulnerability.

    Fixed in 3.28.0

Event History

Aug 19, 2026
Data Sourced
via Red Hat·06:07 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated RDP client can trigger the flaw by sending a malformed Client Audio Formats PDU. The affected component is the FreeRDP server-side rdpsnd audio channel handling.

2

What malformed input triggers the failure?

A Client Audio Formats PDU that causes a parsing error, such as a cbSize value larger than the remaining record, can free the client format allocation while leaving its pointer and count in the server context.

3

What is the impact after a malformed PDU is processed?

When the RDP session is torn down, rdpsnd_server_context_free may free the same allocation again. This reliably terminates the server and may cause allocator-dependent heap corruption.

4

Which versions contain the fix?

The issue is fixed in FreeRDP version 3.28.0. Versions prior to 3.28.0 are affected according to the available information.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203