Security Advisory

CVE-2026-22857

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-01-14 17:53:54
Last updated 2026-02-26 15:04:08
Assigner GitHub_M
State PUBLISHED

Description

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap use-after-free occurs in irp_thread_func because the IRP is freed by irp->Complete() and then accessed again on the error path. This vulnerability is fixed in 3.20.1.