CVE-2026-91957

FreeRDP before 3.31.0 contains a use-after-free vulnerability in the smartcard RDPDR device handler when worker thread creation fails after device registration. Attackers can trigger thread creation failure during channel setup to cause device pointer deallocation while devman retains a reference, leading to crash or code execution.

Scoring

Severity
LOW
CVSS base score
3.1
CVSS vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
EPSS probability
0.33%
CWE
CWE-416
Published
2026-09-15
Last modified
2026-09-17

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs