CVE-2026-67299
CVE-2026-67299: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityMedium6.5
Medium [CVE-2026-67299] Denial of Service via crafted WindowIcon async message
CVE-2026-67299Source published Source updated
FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled (e.g. xfreerdp /async-update). In update_message_WindowIcon() a shallow CopyMemory() overwrites a freshly allocated lParam->iconInfo with the parser-owned windowIcon->iconInfo pointer. After the parser callback returns, update_recv_window_info_order() frees window_icon.iconInfo, but the queued async message still retains and later dispatches that stale pointer. A malicious or compromised RDP server sending a crafted RAIL Window Alternate Secondary Order with WINDOW_ORDER_ICON can trigger use-after-free, leading to memory corruption and client crash. A flaw was found in FreeRDP. A malicious or compromised Remote Desktop Protocol (RDP) server…
- Affected products in this advisory
- Red Hat Enterprise Linux 10.0 Extended Update Support
- Red Hat Enterprise Linux 7 Extended Lifecycle Support
- Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
- Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
9 more entries in the full advisory.
- Source-reported affected versions
- < 3.29.0
- Source-reported fixed versions
- freerdp-2:3.10.3-12.el10_2.8
- freerdp-2:3.10.3-3.el10_0.11
- freerdp-0:2.1.1-5.el7_9.11
- freerdp-2:2.11.7-11.el8_10
18 more entries in the full advisory.
- Mitigation guidance
- To mitigate this issue, avoid connecting to untrusted RDP servers. Additionally, refrain from using the `/async-update` command-line option when launching FreeRDP clients, as this feature is required to trigger the vulnerability.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.