FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock. Authenticated clients can race AUDIN channel closure messages against DRDYNVC data parsing to trigger heap-use-after-free when accessing freed channel objects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 15 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock. Authenticated clients can race AUDIN channel closure messages against DRDYNVC data parsing to trigger heap-use-after-free when accessing freed channel objects. | |
| Title | FreeRDP Server before 3.31.0 Use-After-Free via DRDYNVC | |
| First Time appeared |
Freerdp
Freerdp freerdp |
|
| Weaknesses | CWE-362 | |
| CPEs | cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Freerdp
Freerdp freerdp |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T15:18:05.774Z
Reserved: 2026-09-15T11:07:01.913Z
Link: CVE-2026-91947
No data.
Status : Received
Published: 2026-09-15T16:17:48.353
Modified: 2026-09-15T16:17:48.353
Link: CVE-2026-91947
No data.
OpenCVE Enrichment
No data.
Weaknesses