<Vulnerability name="CVE-2026-91947">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-09-15T15:18:05</PublicDate>
    <Bugzilla id="2533942" url="https://bugzilla.redhat.com/show_bug.cgi?id=2533942" xml:lang="en:us">
FreeRDP: FreeRDP: Use-after-free vulnerability in DRDYNVC parser leads to memory corruption
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>7.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-825</CWE>
    <Details xml:lang="en:us" source="Mitre">
FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock. Authenticated clients can race AUDIN channel closure messages against DRDYNVC data parsing to trigger heap-use-after-free when accessing freed channel objects.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in FreeRDP server. This use-after-free vulnerability exists in the DRDYNVC parser, where a channel pointer is dereferenced after its synchronization lock has been released. An authenticated client can exploit this by racing AUDIN channel closure messages against DRDYNVC data parsing, leading to memory corruption. This could potentially result in arbitrary code execution or a denial of service.
    </Details>
    <Mitigation xml:lang="en:us">
The vulnerability requires an authenticated client to interact with the FreeRDP server. To mitigate this issue, restrict network access to the FreeRDP server to only trusted clients and networks. If the FreeRDP server functionality is not required, consider disabling or uninstalling the FreeRDP server component to eliminate the attack surface.
    </Mitigation>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:10">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <FixState>Affected</FixState>
        <PackageName>freerdp</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:6">
        <ProductName>Red Hat Enterprise Linux 6</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>freerdp</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:7">
        <ProductName>Red Hat Enterprise Linux 7</ProductName>
        <FixState>Affected</FixState>
        <PackageName>freerdp</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:8">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <FixState>Affected</FixState>
        <PackageName>freerdp</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <FixState>Affected</FixState>
        <PackageName>freerdp</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-91947
https://nvd.nist.gov/vuln/detail/CVE-2026-91947
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-6mpx-c8rj-whj5
https://www.vulncheck.com/advisories/freerdp-server-before-3.31.0-use-after-free-via-drdynvc
    </References>
</Vulnerability>