NIXPKGS-2026-0047 published on 20 Jan 2026 CVE-2026-23884 updated 2 days, 12 hours ago by @LeSuisse Activity log Created automatic suggestion 2 days, 18 hours ago @LeSuisse accepted as draft 2 days, 12 hours ago @LeSuisse published on GitHub 2 days, 12 hours ago Heap-use-after-free in gdi_set_bounds FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, offscreen bitmap deletion leaves `gdi->drawing` pointing to freed memory, causing UAF when related update packets arrive. A malicious server can trigger a client‑side use after free, causing a crash (DoS) and potential heap corruption with code‑execution risk depending on allocator behavior and surrounding heap layout. Version 3.21.0 contains a patch for the issue. Affected products FreeRDP ==< 3.21.0 Matching in nixpkgs pkgs.freerdp Remote Desktop Protocol Client nixos-unstable 3.17.2 nixpkgs-unstable 3.17.2 nixos-unstable-small 3.17.2 nixos-25.05 3.15.0 nixos-25.05-small 3.15.0 nixpkgs-25.05-darwin 3.15.0 Package maintainers: 1 @peterhoeg Peter Hoeg <peter@hoeg.com>
CVE-2026-23884 updated 2 days, 12 hours ago by @LeSuisse Activity log Created automatic suggestion 2 days, 18 hours ago @LeSuisse accepted as draft 2 days, 12 hours ago @LeSuisse published on GitHub 2 days, 12 hours ago Heap-use-after-free in gdi_set_bounds FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, offscreen bitmap deletion leaves `gdi->drawing` pointing to freed memory, causing UAF when related update packets arrive. A malicious server can trigger a client‑side use after free, causing a crash (DoS) and potential heap corruption with code‑execution risk depending on allocator behavior and surrounding heap layout. Version 3.21.0 contains a patch for the issue. Affected products FreeRDP ==< 3.21.0 Matching in nixpkgs pkgs.freerdp Remote Desktop Protocol Client nixos-unstable 3.17.2 nixpkgs-unstable 3.17.2 nixos-unstable-small 3.17.2 nixos-25.05 3.15.0 nixos-25.05-small 3.15.0 nixpkgs-25.05-darwin 3.15.0 Package maintainers: 1 @peterhoeg Peter Hoeg <peter@hoeg.com>
pkgs.freerdp Remote Desktop Protocol Client nixos-unstable 3.17.2 nixpkgs-unstable 3.17.2 nixos-unstable-small 3.17.2 nixos-25.05 3.15.0 nixos-25.05-small 3.15.0 nixpkgs-25.05-darwin 3.15.0