Security Advisory

CVE-2026-22856

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-01-14 17:53:04
Last updated 2026-02-26 15:04:09
Assigner GitHub_M
State PUBLISHED

Description

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race in the serial channel IRP thread tracking allows a heap use‑after‑free when one thread removes an entry from serial->IrpThreads while another reads it. This vulnerability is fixed in 3.20.1.