FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_AppUpdateWindowFromSurface` reuses a cached `XImage` whose `data` pointer references a freed RDPGFX surface buffer, because `gdi_DeleteSurface` frees `surface->data` without invalidating the `appWindow->image` that aliases it. Version 3.23.0 fixes the issue.
Metrics
Affected Vendors & Products
References
History
Wed, 25 Feb 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_AppUpdateWindowFromSurface` reuses a cached `XImage` whose `data` pointer references a freed RDPGFX surface buffer, because `gdi_DeleteSurface` frees `surface->data` without invalidating the `appWindow->image` that aliases it. Version 3.23.0 fixes the issue. | |
| Title | FreeRDP has heap-use-after-free in xf_AppUpdateWindowFromSurface (stale XImage) | |
| Weaknesses | CWE-416 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-25T20:32:42.458Z
Reserved: 2026-02-09T17:13:54.065Z
Link: CVE-2026-25955
No data.
Status : Received
Published: 2026-02-25T21:16:41.857
Modified: 2026-02-25T21:16:41.857
Link: CVE-2026-25955
No data.
OpenCVE Enrichment
No data.