Medium [CVE-2026-67299] Denial of Service via crafted WindowIcon async message
This medium-severity Red Hat Linux advisory covers CVE-2026-67299 affecting Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published Record updated
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled (e.g. xfreerdp /async-update). In update_message_WindowIcon() a shallow CopyMemory() overwrites a freshly allocated lParam->iconInfo with the parser-owned windowIcon->iconInfo pointer.
After the parser callback returns, update_recv_window_info_order() frees window_icon.iconInfo, but the queued async message still retains and later dispatches that stale pointer.
A malicious or compromised RDP server sending a crafted RAIL Window Alternate Secondary Order with WINDOW_ORDER_ICON can trigger use-after-free, leading to memory corruption and client crash. A flaw was found in FreeRDP.
A malicious or compromised Remote Desktop Protocol (RDP) server can exploit a heap use-after-free vulnerability when a client connects with asynchronous updates enabled. This leads to memory corruption and a denial of service on the client system, but requires user interaction with a compromised server.
Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-416.
- < 3.29.0
Official advisory · high-confidence parse· fetched 27 days ago·verify at source
- freerdp-2:3.10.3-12.el10_2.8
- freerdp-2:3.10.3-3.el10_0.11
- freerdp-0:2.1.1-5.el7_9.11
- freerdp-2:2.11.7-11.el8_10
- freerdp-2:2.2.0-14.el8_4.2
- freerdp-2:2.2.0-7.el8_6.11
- freerdp-2:2.2.0-12.el8_8.10
- freerdp-2:2.11.7-7.el9_8.5
- freerdp-2:2.4.1-6.el9_2.11
- freerdp-2:2.11.2-1.el9_4.10
- freerdp-2:2.11.7-1.el9_6.12
- RHSA-2026:54486
- RHSA-2026:58711
- RHSA-2026:62401
- RHSA-2026:54485
- RHSA-2026:60173
- RHSA-2026:61250
- RHSA-2026:61251
- RHSA-2026:54487
- RHSA-2026:58712
- RHSA-2026:58710
- RHSA-2026:58713
Official advisory · high-confidence parse· fetched 27 days ago·verify at source
Mitigation checklist
- To mitigate this issue, avoid connecting to untrusted RDP servers. Additionally, refrain from using the `/async-update` command-line option when launching FreeRDP clients, as this feature is required to trigger the vulnerability.
Official advisory · high-confidence parse· fetched 27 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.