Executive brief
FreeRDP is an open-source tool used to connect to remote computers via the Remote Desktop Protocol. A vulnerability in how the software handles mouse cursor data allows a malicious server to crash a user's connection or potentially take control of their computer. This could lead to service disruptions or the theft of sensitive information if a user connects to an untrusted server.
Technical details
A use-after-free (UAF) vulnerability exists in FreeRDP's X11 client due to a double-free condition in the `xf_Pointer_New` function. When `freerdp_image_copy_from_pointer_data` fails, the `cursorPixels` buffer is freed; however, the subsequent error handling path in `update_pointer_color` calls `pointer_free`, which invokes `xf_Pointer_Free` and attempts to free the same buffer again. A malicious RDP server can exploit this by sending specially crafted pointer updates to a client. This can result in a denial-of-service (crash) or potentially remote code execution depending on the heap layout and allocator behavior. The issue is fixed in version 3.21.0.
Affected products
- FreeRDP FreeRDP < 3.21.0
Timeline
- 2026-01-19: disclosed
- 2026-01-19: advisory
- 2026-01-19: patched
References
- https://github.com/FreeRDP/FreeRDP/blob/3370e30e92a021eb680892dda14d642bc8b8727c/client/X11/xf_graphics.c
- https://github.com/FreeRDP/FreeRDP/blob/3370e30e92a021eb680892dda14d642bc8b8727c/client/X11/xf_graphics.c
- https://github.com/FreeRDP/FreeRDP/blob/3370e30e92a021eb680892dda14d642bc8b8727c/libfreerdp/cache/pointer.c
- https://github.com/FreeRDP/FreeRDP/releases/tag/3.21.0
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-qcrr-85qx-4p6x
- https://access.redhat.com/errata/RHSA-2026:2048
- https://access.redhat.com/errata/RHSA-2026:2081