<Vulnerability name="CVE-2026-56297">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-07-08T13:49:01</PublicDate>
    <Bugzilla id="2498073" url="https://bugzilla.redhat.com/show_bug.cgi?id=2498073" xml:lang="en:us">
FreeRDP: FreeRDP: Remote code execution or denial of service via use-after-free race condition
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>5.6</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-364</CWE>
    <Details xml:lang="en:us" source="Mitre">
FreeRDP before 3.22.0 contains a use-after-free vulnerability in dvcman_channel_close and dvcman_call_on_receive due to improper synchronization of channel_callback access. A malicious RDP server can trigger a race condition by sending DYNVC_DATA and DYNVC_CLOSE messages concurrently, causing heap-use-after-free in the drdynvc client thread and potentially enabling remote code execution or denial of service.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in FreeRDP. A malicious Remote Desktop Protocol (RDP) server can exploit a use-after-free vulnerability due to improper synchronization of channel callback access. By sending DYNVC_DATA and DYNVC_CLOSE messages concurrently, a race condition can be triggered in the drdynvc client thread, leading to heap-use-after-free. This could potentially enable remote code execution or cause a denial of service.
    </Details>
    <Statement xml:lang="en:us">
This Moderate impact flaw in FreeRDP allows a malicious RDP server to trigger a use-after-free condition on the client by exploiting a race condition during dynamic virtual channel closure. This could lead to remote code execution or denial of service on the client system when connecting to a compromised or untrusted RDP server.
    </Statement>
    <Mitigation xml:lang="en:us">
Configure host-based firewalls (e.g., firewalld) or network egress filtering so that the workstation can only initiate outbound RDP connections (typically TCP 3389) to known, trusted internal RDP gateways or corporate servers. Blocking outbound RDP to the wider internet neutralizes the threat of users accidentally connecting to malicious external endpoints.
    </Mitigation>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:10">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <FixState>Affected</FixState>
        <PackageName>freerdp</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:6">
        <ProductName>Red Hat Enterprise Linux 6</ProductName>
        <FixState>Out of support scope</FixState>
        <PackageName>freerdp</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:7">
        <ProductName>Red Hat Enterprise Linux 7</ProductName>
        <FixState>Affected</FixState>
        <PackageName>freerdp</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:8">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <FixState>Affected</FixState>
        <PackageName>freerdp</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <FixState>Affected</FixState>
        <PackageName>freerdp</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-56297
https://nvd.nist.gov/vuln/detail/CVE-2026-56297
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-3mv2-5q57-2v8h
https://www.vulncheck.com/advisories/freerdp-use-after-free-via-race-condition-in-drdynvc-channel-callback
    </References>
</Vulnerability>