Description
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `rail_window_free` dereferences a freed `xfAppWindow` pointer during `HashTable_Free` cleanup because `xf_rail_window_common` calls `free(appWindow)` on title allocation failure without first removing the entry from the `railWindows` hash table, leaving a dangling pointer that is freed again on disconnect. Version 3.23.0 fixes the vulnerability.
Problem types
Product status
References
github.com/...reeRDP/security/advisories/GHSA-crqx-g6x5-rx47
github.com/...ommit/b4f0f0a18fe53aa8d47d062f91471f4e9c5e0d51
github.com/...2b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.c
github.com/...2b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.c
github.com/...2b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.c
github.com/...2b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.c
github.com/...2b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.c
github.com/...2b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.c