FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, aAsynchronous bulk transfer completions can use a freed channel callback after URBDRC channel close, leading to a use after free in urb_write_completion. This vulnerability is fixed in 3.22.0.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:6340 https://access.redhat.com/errata/RHSA-2026:6340
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:6727 https://access.redhat.com/errata/RHSA-2026:6727
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:6743 https://access.redhat.com/errata/RHSA-2026:6743
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:6799 https://access.redhat.com/errata/RHSA-2026:6799
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:6918 https://access.redhat.com/errata/RHSA-2026:6918
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:6958 https://access.redhat.com/errata/RHSA-2026:6958
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2026:9640 https://access.redhat.com/errata/RHSA-2026:9640
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:9641 https://access.redhat.com/errata/RHSA-2026:9641