Race Condition Vulnerability in FreeRDP by FreeRDP Team
CVE-2026-22851
What is CVE-2026-22851?
FreeRDP, an open-source implementation of the Remote Desktop Protocol, is affected by a race condition vulnerability stemming from improper management of dynamic virtual channels. This issue occurs between the RDPGFX dynamic virtual channel thread and the SDL render thread, which can lead to a heap use-after-free situation. An escaped pointer to the SDL_Surface, specifically 'sdl->primary', is accessed after being freed during RDPGFX handling. This creates potential security risks in affected versions, with a fix implemented in version 3.20.1.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
FreeRDP < 3.20.1
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
