CVE-2026-24683

Source
https://cve.org/CVERecord?id=CVE-2026-24683
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-24683.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-24683
Aliases
  • GHSA-45pf-68pj-fg8q
Downstream
Related
Published
2026-02-09T18:22:17.636Z
Modified
2026-07-22T00:30:12.758232Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
FreeRDP has a heap-use-after-free in ainput_send_input_event
Details

FreeRDP is a free implementation of the Remote Desktop Protocol. ainputsendinputevent caches channelcallback in a local variable and later uses it without synchronization; a concurrent channel close can free or reinitialize the callback, leading to a use after free. Prior to 3.22.0, This vulnerability is fixed in 3.22.0.

Database specific
{
    "cwe_ids": [
        "CWE-416"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/24xxx/CVE-2026-24683.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/freerdp/freerdp

Affected ranges

Type
GIT
Repo
https://github.com/freerdp/freerdp
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
{
    "cpe": "cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*",
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "3.22.0"
        }
    ]
}

Affected versions

1.*
1.0-beta1
1.0-beta2
1.0-beta4
1.0-beta5
1.0.0
1.0.1
1.1.0-beta+2013071101
1.1.0-beta1
1.1.0-beta1+android2
1.1.0-beta1+android3
1.1.0-beta1+android4
1.1.0-beta1+android5
1.1.0-beta1+ios1
1.1.0-beta1+ios2
1.1.0-beta1+ios3
1.1.0-beta1+ios4
1.2.0-beta1+android7
1.2.0-beta1+android9
2.*
2.0.0
2.0.0-beta1+android10
2.0.0-beta1+android11
2.0.0-rc0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
3.*
3.0.0
3.0.0-beta1
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-rc0
3.1.0
3.2.0
3.3.0
3.4.0
3.5.0
3.5.1

Database specific

vanir_signatures_modified
"2026-07-22T00:30:12Z"
vanir_signatures
[
    {
        "signature_type": "Function",
        "target": {
            "file": "channels/ainput/client/ainput_main.c",
            "function": "terminate_plugin_cb"
        },
        "deprecated": false,
        "source": "https://github.com/freerdp/freerdp/commit/d9ca272dce7a776ab475e9b1a8e8c3d2968c8486",
        "id": "CVE-2026-24683-354f5de4",
        "signature_version": "v1",
        "digest": {
            "function_hash": "231145014262627374288810511893708103758",
            "length": 107.0
        }
    },
    {
        "signature_type": "Function",
        "target": {
            "file": "channels/ainput/client/ainput_main.c",
            "function": "init_plugin_cb"
        },
        "deprecated": false,
        "source": "https://github.com/freerdp/freerdp/commit/d9ca272dce7a776ab475e9b1a8e8c3d2968c8486",
        "id": "CVE-2026-24683-abd15a5e",
        "signature_version": "v1",
        "digest": {
            "function_hash": "13714948715699845688337591421337435254",
            "length": 390.0
        }
    },
    {
        "signature_type": "Function",
        "target": {
            "file": "channels/ainput/client/ainput_main.c",
            "function": "ainput_on_close"
        },
        "deprecated": false,
        "source": "https://github.com/freerdp/freerdp/commit/d9ca272dce7a776ab475e9b1a8e8c3d2968c8486",
        "id": "CVE-2026-24683-ca6f3bbe",
        "signature_version": "v1",
        "digest": {
            "function_hash": "99919897665195191089243943723051613731",
            "length": 119.0
        }
    },
    {
        "signature_type": "Function",
        "target": {
            "file": "channels/ainput/client/ainput_main.c",
            "function": "ainput_send_input_event"
        },
        "deprecated": false,
        "source": "https://github.com/freerdp/freerdp/commit/d9ca272dce7a776ab475e9b1a8e8c3d2968c8486",
        "id": "CVE-2026-24683-e7227a64",
        "signature_version": "v1",
        "digest": {
            "function_hash": "94321970788608289267341130106720511969",
            "length": 1208.0
        }
    },
    {
        "signature_type": "Line",
        "target": {
            "file": "channels/ainput/client/ainput_main.c"
        },
        "deprecated": false,
        "source": "https://github.com/freerdp/freerdp/commit/d9ca272dce7a776ab475e9b1a8e8c3d2968c8486",
        "id": "CVE-2026-24683-ea27110f",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "190008562544560410057996040179045617904",
                "32410127961803529645102041636569091932",
                "263622678584840086625138331179598292838",
                "78952569010251756559654199559014249392",
                "192217900890910348699107543146991136443",
                "100040035760761372901590763219375817986",
                "283336532898596626863141261351427786572",
                "189278407769205436471353303806515270909",
                "41330364526561249864078830867969167481",
                "269444784834428584387317466962975139895",
                "50971260311667431194239993926883094731",
                "23389515418715043279555028830379050874",
                "289837562978570126788476283403392635270",
                "106850822759930995026484604654817997461",
                "7490738671224804822885045216130463044",
                "89845916161951227519149045396374288916",
                "110391441216400260112646077383532709962",
                "254487480556233576628067000268809709867",
                "43540778647497586731195971230069471738",
                "224960808706221309121668606591701126648",
                "320206725915132738739340217548782846863",
                "270736709479832385388670748443899962740",
                "176277657062853123513029135939854934393",
                "254559166797317042628664685366468621754",
                "301016417360366077367354524156799749674",
                "280830583809729078019581994720155483686",
                "333438647880964178900629698382426216045",
                "72701564798101226867744280368213707141",
                "38607579193453593768298688222007931436",
                "15334660753543824634366275565201532266",
                "95823035845490033980037638611508916349",
                "156402952057767365144242727742455676320",
                "128027939219830696636233459706457943504",
                "16696346751369529762746651068664870269",
                "129240731216700604041579483401526967462",
                "109395973628782316242219075267047304230",
                "170509098882001182024775074354832925081",
                "131692657054947089253291413396162498801",
                "52262162978670727282979115380484171399",
                "179355937223625007115175514789164386140",
                "194348034682890949945814167960071556322",
                "301896855931371698122387169573893539904",
                "184587014933658832099099333781490239502"
            ],
            "threshold": 0.9
        }
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-24683.json"