FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, a double-free vulnerability in kerberos_AcceptSecurityContext() and kerberos_InitializeSecurityContextA() (WinPR, winpr/libwinpr/sspi/Kerberos/kerberos.c) can cause a crash in any FreeRDP clients on systems where Kerberos and/or Kerberos U2U is configured (Samba AD member, or krb5 for NFS). The crash is triggered during NLA connection teardown and requires a failed authentication attempt. This issue has been patched in version 3.24.2.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade freerdp | Apr 1, 2026 | Mar 30, 2026 |
| Amazon_linux_2023 | — | Upgrade freerdp-libs-debuginfoUpgrade freerdp-serverUpgrade freerdp-server-debuginfoUpgrade freerdp-debuginfoUpgrade libwinprUpgrade freerdp-libsUpgrade freerdp-develUpgrade freerdpUpgrade freerdp-debugsourceUpgrade libwinpr-develUpgrade libwinpr-debuginfo | Apr 14, 2026 | Mar 30, 2026 |
| Debian | — | Upgrade freerdp3 | Jul 23, 2026 | Jul 23, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Mar 30, 2026 |
| Ubuntu | — | Upgrade freerdp3-x11Upgrade freerdp-x11Upgrade libfreerdp3-3 | Jul 21, 2026 | Jul 20, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub