FreeRDP has a NULL Pointer Dereference in rdp_write_logon_info_v2()
Published Feb 9, 2026
6.9
MEDIUMCVSS 4.0
EPSS 0.50%
Description
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, a NULL pointer dereference vulnerability in rdp_write_logon_info_v2() allows a malicious RDP server to crash FreeRDP proxy by sending a specially crafted LogonInfoV2 PDU with cbDomain=0 or cbUserName=0. This vulnerability is fixed in 3.22.0.
Affected products
-
- Version < 3.22.0StatusaffectedConstraints-
- Version
No data.
Red Hat Enterprise Linux 10
freerdp-2:3.10.3-12.el10_2.2
Fixed · RHSA-2026:19033
Red Hat Enterprise Linux 10
freerdp-2:3.10.3-5.el10_1.5
Fixed · RHSA-2026:6799
Red Hat Enterprise Linux 10.0 Extended Update Support
freerdp-2:3.10.3-3.el10_0.5
Fixed · RHSA-2026:6743
Red Hat Enterprise Linux 7 Extended Lifecycle Support
freerdp-0:2.1.1-5.el7_9.7
Fixed · RHSA-2026:11323
Red Hat Enterprise Linux 8
freerdp-2:2.11.7-6.el8_10
Fixed · RHSA-2026:6918
Red Hat Enterprise Linux 8.2 Advanced Update Support
freerdp-2:2.0.0-46.rc4.el8_2.10
Fixed · RHSA-2026:10734
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
freerdp-2:2.2.0-12.el8_4
Fixed · RHSA-2026:10735
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
freerdp-2:2.2.0-12.el8_4
Fixed · RHSA-2026:10735
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
freerdp-2:2.2.0-7.el8_6.5
Fixed · RHSA-2026:10951
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
freerdp-2:2.2.0-7.el8_6.5
Fixed · RHSA-2026:10951
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
freerdp-2:2.2.0-7.el8_6.5
Fixed · RHSA-2026:10951
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
freerdp-2:2.2.0-12.el8_8.5
Fixed · RHSA-2026:10076
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
freerdp-2:2.2.0-12.el8_8.5
Fixed · RHSA-2026:10076
Red Hat Enterprise Linux 9
freerdp-2:2.11.7-1.el9_7.5
Fixed · RHSA-2026:6340
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
freerdp-2:2.4.1-3.el9_0.4
Fixed · RHSA-2026:9640
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
freerdp-2:2.4.1-6.el9_2.6
Fixed · RHSA-2026:9641
Red Hat Enterprise Linux 9.4 Extended Update Support
freerdp-2:2.11.2-1.el9_4.5
Fixed · RHSA-2026:6958
Red Hat Enterprise Linux 9.6 Extended Update Support
freerdp-2:2.11.7-1.el9_6.7
Fixed · RHSA-2026:6727
Red Hat Enterprise Linux 6
freerdp
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | freerdp-2:3.10.3-12.el10_2.2 | Fixed | RHSA-2026:19033 |
| Red Hat Enterprise Linux 10 | freerdp-2:3.10.3-5.el10_1.5 | Fixed | RHSA-2026:6799 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | freerdp-2:3.10.3-3.el10_0.5 | Fixed | RHSA-2026:6743 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | freerdp-0:2.1.1-5.el7_9.7 | Fixed | RHSA-2026:11323 |
| Red Hat Enterprise Linux 8 | freerdp-2:2.11.7-6.el8_10 | Fixed | RHSA-2026:6918 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | freerdp-2:2.0.0-46.rc4.el8_2.10 | Fixed | RHSA-2026:10734 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | freerdp-2:2.2.0-12.el8_4 | Fixed | RHSA-2026:10735 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | freerdp-2:2.2.0-12.el8_4 | Fixed | RHSA-2026:10735 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | freerdp-2:2.2.0-7.el8_6.5 | Fixed | RHSA-2026:10951 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | freerdp-2:2.2.0-7.el8_6.5 | Fixed | RHSA-2026:10951 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | freerdp-2:2.2.0-7.el8_6.5 | Fixed | RHSA-2026:10951 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | freerdp-2:2.2.0-12.el8_8.5 | Fixed | RHSA-2026:10076 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | freerdp-2:2.2.0-12.el8_8.5 | Fixed | RHSA-2026:10076 |
| Red Hat Enterprise Linux 9 | freerdp-2:2.11.7-1.el9_7.5 | Fixed | RHSA-2026:6340 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | freerdp-2:2.4.1-3.el9_0.4 | Fixed | RHSA-2026:9640 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | freerdp-2:2.4.1-6.el9_2.6 | Fixed | RHSA-2026:9641 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | freerdp-2:2.11.2-1.el9_4.5 | Fixed | RHSA-2026:6958 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | freerdp-2:2.11.7-1.el9_6.7 | Fixed | RHSA-2026:6727 |
| Red Hat Enterprise Linux 6 | freerdp | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Availability impact is limited to the FreeRDP instance on Red Hat Products. General system availability is not at risk.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Feb 10, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Feb–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.50% (0.00496) | 40.29th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.47% (0.00467) | 36.63th | v5 (v2026.06.15) |
| Feb 10, 2026 | 0.04% (0.00044) | 13.19th | v4 (v2025.03.14) |
References (6)
- https://access.redhat.com/security/cve/CVE-2026-23948 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2438207 Issue Tracking
- https://github.com/FreeRDP/FreeRDP/commit/4d44e3c097656a8b9ec696353647b0888ca45860 x_refsource_MISCPatch
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-6f3c-qvqq-2px5 x_refsource_CONFIRMPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-23948
- https://www.cve.org/CVERecord?id=CVE-2026-23948
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-23948 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2438207 | Issue Tracking | |
| https://github.com/FreeRDP/FreeRDP/commit/4d44e3c097656a8b9ec696353647b0888ca45860 | x_refsource_MISCPatch | |
| https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-6f3c-qvqq-2px5 | x_refsource_CONFIRMPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-23948 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-23948 |
Change history (0)
No recorded changes yet.