CVE-2026-44422
Reported by GitHub_M · Published May 29, 2026
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts one non-null NDR pointer ref-id for multiple logical pointer fields without tracking the pointed object's expected NDR type or ownership. When the same ref-id is reused across two pointer fields, the parser assigns the same heap object to both output fields. The generic destructor later walks each field independently and destroys/frees both pointers. This causes a malicious-server-triggerable heap use-after-free / double-free in the FreeRDP client's RDPEAR authentication-redirection path. This vulnerability is fixed in 3.26.0.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| FreeRDP | FreeRDP | < 3.26.0 |
| Red Hat | Red Hat Enterprise Linux AppStream (v. 10) | |
| Red Hat | Red Hat Enterprise Linux CodeReady Linux Builder (v. 10) | |
| Red Hat | Red Hat Enterprise Linux 10 | |
| Red Hat | Red Hat Enterprise Linux 7 | |
| Red Hat | Red Hat Enterprise Linux 6 | |
| Red Hat | Red Hat Enterprise Linux 6 | |
| Red Hat | Red Hat Enterprise Linux 9 | |
| Red Hat | Red Hat Enterprise Linux 8 | |
| Red Hat | Red Hat Enterprise Linux 10 | 2:3.10.3-12.el10_2.6 |
| FreeRDP | FreeRDP | < 3.26.0, < 3.26.0, < 3.26.0 |
| Red Hat | Red Hat Enterprise Linux 7 | |
| Red Hat | Red Hat Enterprise Linux AppStream (v. 10) | |
| Red Hat | Red Hat Enterprise Linux 9 | |
| Red Hat | Red Hat Enterprise Linux 8 | |
| Red Hat | Red Hat Enterprise Linux CodeReady Linux Builder (v. 10) |
Timeline
- May 29, 2026 CVE Published
- May 30, 2026 EPSS Score
- May 31, 2026 EPSS Score
- Jun 1, 2026 EPSS Score
- Jun 1, 2026 Security Advisory
- Jun 5, 2026 EPSS Score
- Jun 8, 2026 Coalition ESS Score
- Jul 7, 2026 Distribution Patch
- Jul 7, 2026 Security Advisory
- Jul 18, 2026 Distribution Patch
- Jul 27, 2026 Distribution Patch
- Jul 27, 2026 Security Advisory
References
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-j9q5-7g8m-jc9v x_refsource_CONFIRM
- https://access.redhat.com/security/cve/CVE-2026-44422 advisory
- https://access.redhat.com/errata/RHSA-2026:46393 advisory
- https://access.redhat.com/errata/RHSA-2026:36203 advisory
- RHBZ#2483467 issue
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44422.json advisory