Skip to content
VulniPulse
Advisory severityMedium6.5Red Hat Linux

Medium [CVE-2026-67299] Denial of Service via crafted WindowIcon async message

This medium-severity Red Hat Linux advisory covers CVE-2026-67299 affecting Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-67299 Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
Red Hat LinuxRed Hat Enterprise Linux
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled (e.g. xfreerdp /async-update). In update_message_WindowIcon() a shallow CopyMemory() overwrites a freshly allocated lParam->iconInfo with the parser-owned windowIcon->iconInfo pointer.

After the parser callback returns, update_recv_window_info_order() frees window_icon.iconInfo, but the queued async message still retains and later dispatches that stale pointer.

A malicious or compromised RDP server sending a crafted RAIL Window Alternate Secondary Order with WINDOW_ORDER_ICON can trigger use-after-free, leading to memory corruption and client crash. A flaw was found in FreeRDP.

A malicious or compromised Remote Desktop Protocol (RDP) server can exploit a heap use-after-free vulnerability when a client connects with asynchronous updates enabled. This leads to memory corruption and a denial of service on the client system, but requires user interaction with a compromised server.

Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-416.

Affected versions
  • < 3.29.0

Official advisory · high-confidence parse· fetched 27 days ago·verify at source

Fixed versions
  • freerdp-2:3.10.3-12.el10_2.8
  • freerdp-2:3.10.3-3.el10_0.11
  • freerdp-0:2.1.1-5.el7_9.11
  • freerdp-2:2.11.7-11.el8_10
  • freerdp-2:2.2.0-14.el8_4.2
  • freerdp-2:2.2.0-7.el8_6.11
  • freerdp-2:2.2.0-12.el8_8.10
  • freerdp-2:2.11.7-7.el9_8.5
  • freerdp-2:2.4.1-6.el9_2.11
  • freerdp-2:2.11.2-1.el9_4.10
  • freerdp-2:2.11.7-1.el9_6.12
  • RHSA-2026:54486
  • RHSA-2026:58711
  • RHSA-2026:62401
  • RHSA-2026:54485
  • RHSA-2026:60173
  • RHSA-2026:61250
  • RHSA-2026:61251
  • RHSA-2026:54487
  • RHSA-2026:58712
  • RHSA-2026:58710
  • RHSA-2026:58713

Official advisory · high-confidence parse· fetched 27 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • To mitigate this issue, avoid connecting to untrusted RDP servers. Additionally, refrain from using the `/async-update` command-line option when launching FreeRDP clients, as this feature is required to trigger the vulnerability.

Official advisory · high-confidence parse· fetched 27 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.