CVE-2026-63652
Description
A flaw was found in FreeRDP. An authenticated Remote Desktop Protocol (RDP) client can send a specially crafted Client Audio Formats Protocol Data Unit (PDU) to the server. This malformed PDU can cause a double-free vulnerability in the rdpsnd_server_recv_formats function, leading to the server reliably terminating. This issue can also result in allocator-dependent heap corruption, which may have further security implications.
Statement
A double-free vulnerability exists in FreeRDP's rdpsnd_server_recv_formats function within the rdpsnd server channel. An authenticated remote RDP client can send a malformed Client Audio Formats PDU with an invalid cbSize parameter, causing memory to be freed without zeroing the client_formats pointer. Upon session teardown, rdpsnd_server_context_free attempts to free the dangling pointer again. This results in server process termination and potential heap corruption, causing a denial of service.
Mitigation
To mitigate this issue, disable audio redirection on the FreeRDP server configuration if remote audio capability is not required.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 6.5 | N/A | N/A |
| Attack Vector | Network | N/A | N/A |
| Attack Complexity | Low | N/A | N/A |
| Privileges Required | Low | N/A | N/A |
| User Interaction | None | N/A | N/A |
| Scope | Unchanged | N/A | N/A |
| Confidentiality | None | N/A | N/A |
| Integrity Impact | None | N/A | N/A |
| Availability Impact | High | N/A | N/A |
Vector
Red Hat: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Understanding the Weakness (CWE)
Availability,Integrity
Technical Impact: DoS: Crash, Exit, or Restart
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.