NIXPKGS-2026-0020 published on 17 Jan 2026 CVE-2026-22852 updated 5 days, 10 hours ago by @LeSuisse Activity log Created automatic suggestion 5 days, 19 hours ago @LeSuisse accepted as draft 5 days, 10 hours ago @LeSuisse published on GitHub 5 days, 10 hours ago FreeRDP has a heap-buffer-overflow in audin_process_formats FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client when processing Audio Input (AUDIN) format lists. audin_process_formats reuses callback->formats_count across multiple MSG_SNDIN_FORMATS PDUs and writes past the newly allocated formats array, causing memory corruption and a crash. This vulnerability is fixed in 3.20.1. Affected products FreeRDP ==< 3.20.1 Matching in nixpkgs pkgs.freerdp Remote Desktop Protocol Client nixos-unstable 3.17.2 nixpkgs-unstable 3.17.2 nixos-unstable-small 3.17.2 nixos-25.05 3.15.0 nixos-25.05-small 3.15.0 nixpkgs-25.05-darwin 3.15.0 Package maintainers: 1 @peterhoeg Peter Hoeg <peter@hoeg.com>
CVE-2026-22852 updated 5 days, 10 hours ago by @LeSuisse Activity log Created automatic suggestion 5 days, 19 hours ago @LeSuisse accepted as draft 5 days, 10 hours ago @LeSuisse published on GitHub 5 days, 10 hours ago FreeRDP has a heap-buffer-overflow in audin_process_formats FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client when processing Audio Input (AUDIN) format lists. audin_process_formats reuses callback->formats_count across multiple MSG_SNDIN_FORMATS PDUs and writes past the newly allocated formats array, causing memory corruption and a crash. This vulnerability is fixed in 3.20.1. Affected products FreeRDP ==< 3.20.1 Matching in nixpkgs pkgs.freerdp Remote Desktop Protocol Client nixos-unstable 3.17.2 nixpkgs-unstable 3.17.2 nixos-unstable-small 3.17.2 nixos-25.05 3.15.0 nixos-25.05-small 3.15.0 nixpkgs-25.05-darwin 3.15.0 Package maintainers: 1 @peterhoeg Peter Hoeg <peter@hoeg.com>
pkgs.freerdp Remote Desktop Protocol Client nixos-unstable 3.17.2 nixpkgs-unstable 3.17.2 nixos-unstable-small 3.17.2 nixos-25.05 3.15.0 nixos-25.05-small 3.15.0 nixpkgs-25.05-darwin 3.15.0