FreeRDP is a free implementation of the Remote Desktop Protocol. ainput_send_input_event caches channel_callback in a local variable and later uses it without synchronization; a concurrent channel close can free or reinitialize the callback, leading to a use after free. Prior to 3.22.0, This vulnerability is fixed in 3.22.0.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:6340 https://access.redhat.com/errata/RHSA-2026:6340
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:6727 https://access.redhat.com/errata/RHSA-2026:6727
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:6743 https://access.redhat.com/errata/RHSA-2026:6743
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:6799 https://access.redhat.com/errata/RHSA-2026:6799
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:6918 https://access.redhat.com/errata/RHSA-2026:6918
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:6958 https://access.redhat.com/errata/RHSA-2026:6958