Security Advisory

CVE-2026-22851

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-01-14 17:43:28
Last updated 2026-01-14 21:03:36
Assigner GitHub_M
State PUBLISHED

Description

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race condition between the RDPGFX dynamic virtual channel thread and the SDL render thread leads to a heap use-after-free. Specifically, an escaped pointer to sdl->primary (SDL_Surface) is accessed after it has been freed during RDPGFX ResetGraphics handling. This vulnerability is fixed in 3.20.1.