VDB

CVE-2026-44422

CVE-2026-44422 PUBLISHED CVSS 7.5 HIGH

Reported by GitHub_M · Published May 29, 2026

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts one non-null NDR pointer ref-id for multiple logical pointer fields without tracking the pointed object's expected NDR type or ownership. When the same ref-id is reused across two pointer fields, the parser assigns the same heap object to both output fields. The generic destructor later walks each field independently and destroys/frees both pointers. This causes a malicious-server-triggerable heap use-after-free / double-free in the FreeRDP client's RDPEAR authentication-redirection path. This vulnerability is fixed in 3.26.0.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
FreeRDPFreeRDP< 3.26.0
Red HatRed Hat Enterprise Linux AppStream (v. 10)
Red HatRed Hat Enterprise Linux CodeReady Linux Builder (v. 10)
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 7
Red HatRed Hat Enterprise Linux 6
Red HatRed Hat Enterprise Linux 6
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 102:3.10.3-12.el10_2.6
FreeRDPFreeRDP< 3.26.0, < 3.26.0, < 3.26.0
Red HatRed Hat Enterprise Linux 7
Red HatRed Hat Enterprise Linux AppStream (v. 10)
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux CodeReady Linux Builder (v. 10)

Timeline

  • May 29, 2026 CVE Published
  • May 30, 2026 EPSS Score
  • May 31, 2026 EPSS Score
  • Jun 1, 2026 EPSS Score
  • Jun 1, 2026 Security Advisory
  • Jun 5, 2026 EPSS Score
  • Jun 8, 2026 Coalition ESS Score
  • Jul 7, 2026 Distribution Patch
  • Jul 7, 2026 Security Advisory
  • Jul 18, 2026 Distribution Patch
  • Jul 27, 2026 Distribution Patch
  • Jul 27, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›