CVE-2026-22857
CRIT 9.8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap use-after-free occurs in irp_thread_func because the IRP is freed by irp->Complete() and then accessed again on the error path. This vulnerability is fixed in 3.20.1.
Affected Applications in Environment
1
freerdp
v2.1.1-5.el7_9
1 device
Affected Devices
1
guru.cluster
Linux