{
  "threat_severity" : "Moderate",
  "public_date" : "2026-02-09T18:20:39Z",
  "bugzilla" : {
    "description" : "freerdp: FreeRDP has a heap-use-after-free in urb_bulk_transfer_cb",
    "id" : "2438210",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2438210"
  },
  "cvss3" : {
    "cvss3_base_score" : "5.3",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
    "status" : "verified"
  },
  "cwe" : "CWE-825",
  "details" : [ "FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, aAsynchronous bulk transfer completions can use a freed channel callback after URBDRC channel close, leading to a use after free in urb_write_completion. This vulnerability is fixed in 3.22.0.", "A heap buffer use after free has been discovered in FreeRDP. Asynchronous bulk transfer completions can use a freed channel callback after URBDRC channel close, leading to a use after free in urb_write_completion." ],
  "statement" : "Availability impact is limited to the FreeRDP instance on Red Hat Products. General system availability is not at risk.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-04-07T00:00:00Z",
    "advisory" : "RHSA-2026:6799",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.1",
    "package" : "freerdp-2:3.10.3-5.el10_1.5"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-05-19T00:00:00Z",
    "advisory" : "RHSA-2026:19033",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "freerdp-2:3.10.3-12.el10_2.2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10.0 Extended Update Support",
    "release_date" : "2026-04-07T00:00:00Z",
    "advisory" : "RHSA-2026:6743",
    "cpe" : "cpe:/o:redhat:enterprise_linux_eus:10.0",
    "package" : "freerdp-2:3.10.3-3.el10_0.5"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-04-07T00:00:00Z",
    "advisory" : "RHSA-2026:6918",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "freerdp-2:2.11.7-6.el8_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-04-01T00:00:00Z",
    "advisory" : "RHSA-2026:6340",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "freerdp-2:2.11.7-1.el9_7.5"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
    "release_date" : "2026-04-22T00:00:00Z",
    "advisory" : "RHSA-2026:9640",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.0",
    "package" : "freerdp-2:2.4.1-3.el9_0.4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
    "release_date" : "2026-04-22T00:00:00Z",
    "advisory" : "RHSA-2026:9641",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.2",
    "package" : "freerdp-2:2.4.1-6.el9_2.6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.4 Extended Update Support",
    "release_date" : "2026-04-08T00:00:00Z",
    "advisory" : "RHSA-2026:6958",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.4",
    "package" : "freerdp-2:2.11.2-1.el9_4.5"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.6 Extended Update Support",
    "release_date" : "2026-04-07T00:00:00Z",
    "advisory" : "RHSA-2026:6727",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.6",
    "package" : "freerdp-2:2.11.7-1.el9_6.7"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Out of support scope",
    "package_name" : "freerdp",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Not affected",
    "package_name" : "freerdp",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-24681\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-24681\nhttps://github.com/FreeRDP/FreeRDP/commit/414f701464929c217f2509bcbd6d2c1f00f7ed73\nhttps://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-ccvv-hg2w-6x9j" ],
  "name" : "CVE-2026-24681",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}