FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, A capture thread sends sample responses using a freed channel callback after a device channel close, leading to a use after free in ecam_channel_write. This vulnerability is fixed in 3.22.0.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:3068 https://access.redhat.com/errata/RHSA-2026:3068
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:4121 https://access.redhat.com/errata/RHSA-2026:4121