Junglewise Threat Intelligence

CVE-2026-23883: FreeRDP use after free in xf_Pointer_New

CVE-2026-23883 · Severity: critical · CVSS 9.8 · Published 2026-01-19

Technologies: FreeRDP. Vendors: FreeRDP.

Executive brief

FreeRDP is an open-source tool used to connect to remote computers via the Remote Desktop Protocol. A vulnerability in how the software handles mouse cursor data allows a malicious server to crash a user's connection or potentially take control of their computer. This could lead to service disruptions or the theft of sensitive information if a user connects to an untrusted server.

Technical details

A use-after-free (UAF) vulnerability exists in FreeRDP's X11 client due to a double-free condition in the `xf_Pointer_New` function. When `freerdp_image_copy_from_pointer_data` fails, the `cursorPixels` buffer is freed; however, the subsequent error handling path in `update_pointer_color` calls `pointer_free`, which invokes `xf_Pointer_Free` and attempts to free the same buffer again. A malicious RDP server can exploit this by sending specially crafted pointer updates to a client. This can result in a denial-of-service (crash) or potentially remote code execution depending on the heap layout and allocator behavior. The issue is fixed in version 3.21.0.

Affected products

  • FreeRDP FreeRDP < 3.21.0

Timeline

  • 2026-01-19: disclosed
  • 2026-01-19: advisory
  • 2026-01-19: patched

References

Related threats