Bug 2533939 (CVE-2026-91957) - CVE-2026-91957 FreeRDP: FreeRDP: Use-after-free vulnerability in smartcard RDPDR device handler leading to denial of service or potential code execution
Summary: CVE-2026-91957 FreeRDP: FreeRDP: Use-after-free vulnerability in smartcard RD...
Keywords:
Status: NEW
Alias: CVE-2026-91957
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2534081 2534082
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-15 15:52 UTC by OSIDB Bzimport
Modified: 2026-09-15 18:28 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-15 15:52:04 UTC
FreeRDP before 3.31.0 contains a use-after-free vulnerability in the smartcard RDPDR device handler when worker thread creation fails after device registration. Attackers can trigger thread creation failure during channel setup to cause device pointer deallocation while devman retains a reference, leading to crash or code execution.


Note You need to log in before you can comment on or make changes to this bug.