Description
FreeRDP before 3.31.0 contains a use-after-free vulnerability in the smartcard RDPDR device handler when worker thread creation fails after device registration. Attackers can trigger thread creation failure during channel setup to cause device pointer deallocation while devman retains a reference, leading to crash or code execution.
Published: 2026-09-15
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free leading to crash or potential code execution
Action: Apply Patch
AI Analysis

Impact

FreeRDP before version 3.31.0 contains a use‑after RDPDR device handler. When a worker thread fails to start after a device is registered, the device pointer is freed while the device manager still holds a reference, resulting in a crash or potentially allowing arbitrary code execution. This vulnerability is a classic example of CWE-416 and involves an invalid memory reference after deallocation, fitting the description of CWE-825.

Affected Systems

FreeRDP releases older than 3.31.0, specifically any installation that device in those versions, are impacted.

Risk and Exploitability

The CVSS score of 2.3 indicates low overall severity. The EPSS score is < 1%, indicating a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation would likely require an attacker to trigger the smartcard channel setup during an RDP session and cause a thread‑creation failure, for which no public exploit exists. Based on the description, the attack vector is inferred to be remote via an RDP connection that initiates a smartcard channel, though precise exploitation conditions are not fully detailed.

Generated by OpenCVE AI on September 20, 2026 at 16:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade FreeRDP to version 3.31.0 or later.
  • If upgrading is not immediately possible, disable the smartcard feature or prevent smartcard channel usage in RDP sessions.
  • Monitor system logs for smartcard channel setup failures or crashes that may indicate exploitation attempts.

Generated by OpenCVE AI on September 20, 2026 at 16:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

threat_severity

Low


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description FreeRDP before 3.31.0 contains a use-after-free vulnerability in the smartcard RDPDR device handler when worker thread creation fails after device registration. Attackers can trigger thread creation failure during channel setup to cause device pointer deallocation while devman retains a reference, leading to crash or code execution.
Title FreeRDP before 3.31.0 Use-After-Free via smartcard worker
First Time appeared Freerdp
Freerdp freerdp
Weaknesses CWE-416
CPEs cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*
Vendors & Products Freerdp
Freerdp freerdp
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T14:56:56.687Z

Reserved: 2026-09-15T11:07:34.399Z

Link: CVE-2026-91957

cve-icon Vulnrichment

Updated: 2026-09-17T14:56:08.587Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T16:17:50.647

Modified: 2026-09-24T12:17:00.363

Link: CVE-2026-91957

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-15T15:18:12Z

Links: CVE-2026-91957 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:30:18Z

Weaknesses