Freerdp: Prior to 3.28.0, rdpsnd_server_recv_formats in channels/rdpsnd/server/rdpsnd_main.c frees context->client_formats on a malformed Client Audio… (CVE-2026-63652)
Description
FreeRDP versions prior to 3.28.0 contain a vulnerability in the rdpsnd_server_recv_formats function where a malformed Client Audio Formats PDU can cause a double free of memory. This issue can be triggered by an authenticated RDP client, leading to server termination and potential heap corruption. The vulnerability is fixed in version 3.28.0.
CVSS v3.1
Score 6.5medium
Affected software
pkg:deb/ubuntu/freerdp?arch=source&distro=xenialpkg:deb/ubuntu/freerdp2?arch=source&distro=esm-infra/bionicpkg:deb/ubuntu/freerdp?arch=source&distro=bionicpkg:deb/ubuntu/freerdp2?arch=source&distro=esm-infra/focalpkg:deb/ubuntu/freerdp2?arch=source&distro=jammypkg:deb/ubuntu/freerdp3?arch=source&distro=noblepkg:deb/ubuntu/freerdp2?arch=source&distro=esm-apps/noblepkg:deb/ubuntu/freerdp3?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
FreeRDP, a Remote Desktop Protocol implementation, has a vulnerability in versions prior to 3.28.0 in the rdpsnd_server_recv_formats function located in channels/rdpsnd/server/rdpsnd_main.c. When processing a malformed Client Audio Formats PDU, the function frees context->client_formats without clearing the pointer or num_client_formats, leaving a dangling pointer. Upon session teardown, rdpsnd_server_context_free attempts to free the same memory again, causing a double free. This results in reliable server termination and may cause allocator-dependent heap corruption. The issue is resolved in FreeRDP version 3.28.0.
Potential Impact
An authenticated RDP client can exploit this vulnerability to cause the FreeRDP server to terminate unexpectedly, resulting in a denial of service. Additionally, the double free condition may lead to heap corruption, which could potentially be leveraged for further exploitation depending on the allocator behavior. There is no indication of confidentiality or integrity impact.
Mitigation Recommendations
A patch is available in FreeRDP version 3.28.0 that fixes this vulnerability. Users should upgrade to version 3.28.0 or later to remediate this issue. No other mitigation actions are specified or required.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-63652
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:Pro:24.04:LTS","Ubuntu:26.04:LTS"]
Threat ID: 6a870a96acd9273b49b5a590
Added to database: 08/20/2026, 14:09:26 UTC
Last enriched: 09/24/2026, 08:20:10 UTC
Last updated: 10/04/2026, 16:08:40 UTC
Views: 74
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.