Junglewise Threat Intelligence

CVE-2026-63652: FreeRDP double-free in audio format handling

CVE-2026-63652 · Severity: medium · CVSS 6.5 · Published 2026-08-19

Technologies: FreeRDP. Vendors: FreeRDP.

Executive brief

FreeRDP is a widely-used open-source implementation of Remote Desktop Protocol (RDP), which allows remote access to computer systems. An authenticated attacker can craft a malicious audio format message to trigger a double-free memory corruption vulnerability in the RDP server, causing it to crash and potentially corrupting heap memory. This disrupts remote access services and could be chained with other exploits for further compromise.

Technical details

The vulnerability is a double-free in the rdpsnd_server_recv_formats function (channels/rdpsnd/server/rdpsnd_main.c). When processing a malformed Client Audio Formats PDU with an oversized cbSize field, the server frees context->client_formats without clearing the pointer or associated num_client_formats counter. Later, when the RDP session ends and rdpsnd_server_context_free is called, the same memory is freed again, causing a heap double-free. The flaw requires an authenticated RDP client connection and reliably crashes the server; allocator-dependent heap corruption may also occur. The fix, available in FreeRDP 3.28.0, adds proper pointer clearing and range validation.

Affected products

  • FreeRDP FreeRDP prior to 3.28.0

Timeline

  • 2026-08-19: disclosed
  • 2026-07-02: patched: Fix merged in PR #12993; version 3.28.0 released

References

Related threats