FreeRDP is a free implementation of the Remote Desktop Protocol. ainputsendinputevent caches channelcallback in a local variable and later uses it without synchronization; a concurrent channel close can free or reinitialize the callback, leading to a use after free. Prior to 3.22.0, This vulnerability is fixed in 3.22.0.
{
"cwe_ids": [
"CWE-416"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/24xxx/CVE-2026-24683.json",
"cna_assigner": "GitHub_M"
}{
"cpe": "cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "3.22.0"
}
]
}"2026-07-22T00:30:12Z"
[
{
"signature_type": "Function",
"target": {
"file": "channels/ainput/client/ainput_main.c",
"function": "terminate_plugin_cb"
},
"deprecated": false,
"source": "https://github.com/freerdp/freerdp/commit/d9ca272dce7a776ab475e9b1a8e8c3d2968c8486",
"id": "CVE-2026-24683-354f5de4",
"signature_version": "v1",
"digest": {
"function_hash": "231145014262627374288810511893708103758",
"length": 107.0
}
},
{
"signature_type": "Function",
"target": {
"file": "channels/ainput/client/ainput_main.c",
"function": "init_plugin_cb"
},
"deprecated": false,
"source": "https://github.com/freerdp/freerdp/commit/d9ca272dce7a776ab475e9b1a8e8c3d2968c8486",
"id": "CVE-2026-24683-abd15a5e",
"signature_version": "v1",
"digest": {
"function_hash": "13714948715699845688337591421337435254",
"length": 390.0
}
},
{
"signature_type": "Function",
"target": {
"file": "channels/ainput/client/ainput_main.c",
"function": "ainput_on_close"
},
"deprecated": false,
"source": "https://github.com/freerdp/freerdp/commit/d9ca272dce7a776ab475e9b1a8e8c3d2968c8486",
"id": "CVE-2026-24683-ca6f3bbe",
"signature_version": "v1",
"digest": {
"function_hash": "99919897665195191089243943723051613731",
"length": 119.0
}
},
{
"signature_type": "Function",
"target": {
"file": "channels/ainput/client/ainput_main.c",
"function": "ainput_send_input_event"
},
"deprecated": false,
"source": "https://github.com/freerdp/freerdp/commit/d9ca272dce7a776ab475e9b1a8e8c3d2968c8486",
"id": "CVE-2026-24683-e7227a64",
"signature_version": "v1",
"digest": {
"function_hash": "94321970788608289267341130106720511969",
"length": 1208.0
}
},
{
"signature_type": "Line",
"target": {
"file": "channels/ainput/client/ainput_main.c"
},
"deprecated": false,
"source": "https://github.com/freerdp/freerdp/commit/d9ca272dce7a776ab475e9b1a8e8c3d2968c8486",
"id": "CVE-2026-24683-ea27110f",
"signature_version": "v1",
"digest": {
"line_hashes": [
"190008562544560410057996040179045617904",
"32410127961803529645102041636569091932",
"263622678584840086625138331179598292838",
"78952569010251756559654199559014249392",
"192217900890910348699107543146991136443",
"100040035760761372901590763219375817986",
"283336532898596626863141261351427786572",
"189278407769205436471353303806515270909",
"41330364526561249864078830867969167481",
"269444784834428584387317466962975139895",
"50971260311667431194239993926883094731",
"23389515418715043279555028830379050874",
"289837562978570126788476283403392635270",
"106850822759930995026484604654817997461",
"7490738671224804822885045216130463044",
"89845916161951227519149045396374288916",
"110391441216400260112646077383532709962",
"254487480556233576628067000268809709867",
"43540778647497586731195971230069471738",
"224960808706221309121668606591701126648",
"320206725915132738739340217548782846863",
"270736709479832385388670748443899962740",
"176277657062853123513029135939854934393",
"254559166797317042628664685366468621754",
"301016417360366077367354524156799749674",
"280830583809729078019581994720155483686",
"333438647880964178900629698382426216045",
"72701564798101226867744280368213707141",
"38607579193453593768298688222007931436",
"15334660753543824634366275565201532266",
"95823035845490033980037638611508916349",
"156402952057767365144242727742455676320",
"128027939219830696636233459706457943504",
"16696346751369529762746651068664870269",
"129240731216700604041579483401526967462",
"109395973628782316242219075267047304230",
"170509098882001182024775074354832925081",
"131692657054947089253291413396162498801",
"52262162978670727282979115380484171399",
"179355937223625007115175514789164386140",
"194348034682890949945814167960071556322",
"301896855931371698122387169573893539904",
"184587014933658832099099333781490239502"
],
"threshold": 0.9
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-24683.json"