CVE-2026-24680
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, sdlPointerNew frees data on failure, then pointerfree calls sdlPointer_Free and frees it again, triggering ASan UAF. This vulnerability is fixed in 3.22.0.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/24xxx/CVE-2026-24680.json, https://github.com/FreeRDP/FreeRDP/commit/c42ecbd183b001e76bfc3614cddfad0034acc758, https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-j893-9wg8-33rc, https://nvd.nist.gov/vuln/detail/CVE-2026-24680
