Skip to main content
EPSS 0.5%top 60%

freerdp2, freerdp3 vulnerabilities (CVE-2026-23948)

0
High
Published: 02/16/2026 (02/16/2026, 10:04:47 UTC)
Source: GCVE Database
Product: freerdp2

Description

Multiple vulnerabilities were identified in FreeRDP versions used in various Ubuntu releases, including memory handling errors, buffer overflows, and use-after-free conditions. These issues could allow attackers to cause denial of service or potentially execute arbitrary code. The vulnerabilities affect FreeRDP2 and FreeRDP3 packages across Ubuntu 18.04 LTS, 20.04 LTS, 22.04 LTS, 24.04 LTS, and 25.10. Official patches are available from Ubuntu, including updates distributed via Ubuntu Pro and Extended Security Maintenance (ESM).

Affected software

Ubuntu:Pro:18.04:LTSmore threats →ghsa
freerdp2
pkg:deb/ubuntu/freerdp2?arch=source&distro=esm-infra/bionic
Affected versions
<2.2.0+dfsg1-0ubuntu0.18.04.4+esm5=2.0.0~git20170725.1.1648deb+dfsg1-1=2.0.0~git20170725.1.1648deb+dfsg1-5=2.0.0~git20170725.1.1648deb+dfsg1-5ubuntu1=2.0.0~git20170725.1.1648deb+dfsg1-5ubuntu2=2.0.0~git20170725.1.1648deb+dfsg1-6=2.0.0~git20170725.1.1648deb+dfsg1-6build1=2.0.0~git20170725.1.1648deb+dfsg1-7=2.0.0~git20170725.1.1648deb+dfsg1-7ubuntu0.1=2.1.1+dfsg1-0ubuntu0.18.04.1=2.2.0+dfsg1-0ubuntu0.18.04.1=2.2.0+dfsg1-0ubuntu0.18.04.2=2.2.0+dfsg1-0ubuntu0.18.04.3=2.2.0+dfsg1-0ubuntu0.18.04.4=2.2.0+dfsg1-0ubuntu0.18.04.4+esm1=2.2.0+dfsg1-0ubuntu0.18.04.4+esm2=2.2.0+dfsg1-0ubuntu0.18.04.4+esm3=2.2.0+dfsg1-0ubuntu0.18.04.4+esm4
Ubuntu:Pro:20.04:LTSmore threats →ghsa
freerdp2
pkg:deb/ubuntu/freerdp2?arch=source&distro=esm-infra/focal
Affected versions
<2.6.1+dfsg1-0ubuntu0.20.04.2+esm3=2.0.0~git20190204.1.2693389a+dfsg1-1=2.0.0~git20190204.1.2693389a+dfsg1-2=2.0.0~git20190204.1.2693389a+dfsg1-2build1=2.0.0~git20190204.1.2693389a+dfsg1-2build2=2.1.1+dfsg1-0ubuntu0.20.04.1=2.2.0+dfsg1-0ubuntu0.20.04.1=2.2.0+dfsg1-0ubuntu0.20.04.2=2.2.0+dfsg1-0ubuntu0.20.04.3=2.2.0+dfsg1-0ubuntu0.20.04.4=2.2.0+dfsg1-0ubuntu0.20.04.5=2.2.0+dfsg1-0ubuntu0.20.04.6=2.6.1+dfsg1-0ubuntu0.20.04.1=2.6.1+dfsg1-0ubuntu0.20.04.2=2.6.1+dfsg1-0ubuntu0.20.04.2+esm1=2.6.1+dfsg1-0ubuntu0.20.04.2+esm2
Ubuntu:22.04:LTSmore threats →ghsa
freerdp2
pkg:deb/ubuntu/freerdp2?arch=source&distro=jammy
Affected versions
<2.6.1+dfsg1-3ubuntu2.10=2.3.0+dfsg1-2build1=2.3.0+dfsg1-2ubuntu1=2.3.0+dfsg1-2ubuntu2=2.4.1+dfsg1-1=2.4.1+dfsg1-1ubuntu1=2.4.1+dfsg1-1ubuntu2=2.5.0+dfsg1-1=2.6.0+dfsg1-1=2.6.1+dfsg1-1=2.6.1+dfsg1-3=2.6.1+dfsg1-3ubuntu1=2.6.1+dfsg1-3ubuntu2=2.6.1+dfsg1-3ubuntu2.1=2.6.1+dfsg1-3ubuntu2.2=2.6.1+dfsg1-3ubuntu2.3=2.6.1+dfsg1-3ubuntu2.4=2.6.1+dfsg1-3ubuntu2.5=2.6.1+dfsg1-3ubuntu2.6=2.6.1+dfsg1-3ubuntu2.7=2.6.1+dfsg1-3ubuntu2.8=2.6.1+dfsg1-3ubuntu2.9
Ubuntu:24.04:LTSmore threats →ghsa
freerdp3
pkg:deb/ubuntu/freerdp3?arch=source&distro=noble
Affected versions
<3.5.1+dfsg1-0ubuntu1.2=3.4.0+dfsg1-0ubuntu2=3.4.0+dfsg1-0ubuntu3=3.4.0+dfsg1-0ubuntu4=3.5.0+dfsg1-0ubuntu1=3.5.1+dfsg1-0ubuntu1=3.5.1+dfsg1-0ubuntu1.1
Ubuntu:Pro:24.04:LTSmore threats →ghsa
freerdp2
pkg:deb/ubuntu/freerdp2?arch=source&distro=esm-apps/noble
Affected versions
<2.11.5+dfsg1-1ubuntu0.1~esm5=2.10.0+dfsg1-1.1ubuntu1=2.11.2+dfsg1-1=2.11.2+dfsg1-1build1=2.11.2+dfsg1-1build3=2.11.5+dfsg1-1build1=2.11.5+dfsg1-1build2=2.11.5+dfsg1-1ubuntu0.1~esm1=2.11.5+dfsg1-1ubuntu0.1~esm2=2.11.5+dfsg1-1ubuntu0.1~esm3=2.11.5+dfsg1-1ubuntu0.1~esm4
Ubuntu:25.10more threats →ghsa
freerdp3
pkg:deb/ubuntu/freerdp3?arch=source&distro=questing
Affected versions
<3.16.0+dfsg-2ubuntu0.1=3.14.0+dfsg-1ubuntu1=3.15.0+dfsg-2.1=3.16.0+dfsg-1ubuntu1=3.16.0+dfsg-2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/10/2026, 13:36:16 UTC

Technical Analysis

Several security flaws were discovered in FreeRDP, including incorrect memory handling leading to NULL pointer dereference (CVE-2026-23948), improper size validation causing buffer overflows (CVE-2026-24491, CVE-2026-24675, CVE-2026-24679, CVE-2026-24682, CVE-2026-24677), and use-after-free vulnerabilities (CVE-2026-24676, CVE-2026-24681, CVE-2026-24678, CVE-2026-24680, CVE-2026-24683, CVE-2026-24684). These vulnerabilities affect FreeRDP2 and FreeRDP3 packages on multiple Ubuntu LTS and interim releases, with some issues specific to Ubuntu 24.04 LTS and 25.10. The flaws could be exploited to cause denial of service or execute arbitrary code. Ubuntu has released security updates and patches for affected versions, including through Ubuntu Pro and ESM channels.

Potential Impact

The vulnerabilities can be exploited to cause denial of service conditions or potentially allow arbitrary code execution on affected systems running vulnerable FreeRDP versions. This could lead to system instability or compromise if exploited. The impact varies by vulnerability but includes memory corruption and buffer overflow issues that attackers might leverage.

Mitigation Recommendations

Official patches are available and should be applied promptly. Ubuntu has released updated package versions fixing these vulnerabilities for all affected releases, including Ubuntu 18.04 LTS, 20.04 LTS, 22.04 LTS, 24.04 LTS, and 25.10. Users should update FreeRDP packages via standard system updates or through Ubuntu Pro and ESM services where applicable. No additional mitigation steps are indicated beyond applying these updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
USN-8042-1
Osv Schema Version
1.7.0
Ecosystems
["Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:Pro:24.04:LTS","Ubuntu:25.10"]

Threat ID: 6aa2af82acd9273b4925b3a7

Added to database: 09/10/2026, 13:24:18 UTC

Last enriched: 09/10/2026, 13:36:16 UTC

Last updated: 09/10/2026, 19:36:53 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses