CVE-2026-23948: NixOS vulnerability analysis and mitigation
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, a NULL pointer dereference vulnerability in rdp_write_logon_info_v2() allows a malicious RDP server to crash FreeRDP proxy by sending a specially crafted LogonInfoV2 PDU with cbDomain=0 or cbUserName=0. This vulnerability is fixed in 3.22.0.
Source: NVD
Related NixOS vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2026-21010
HIGH
7.8
NixOS
android
No
No
Apr 13, 2026
CVE-2026-21012
MEDIUM
6.8
NixOS
android
No
No
Apr 13, 2026
CVE-2026-21011
MEDIUM
5.4
NixOS
android
No
No
Apr 13, 2026
CVE-2026-21008
MEDIUM
5.1
NixOS
android
No
No
Apr 13, 2026
CVE-2026-21007
MEDIUM
4.4
NixOS
android
No
No
Apr 13, 2026
Free Vulnerability Assessment
Benchmark your Cloud Security Posture
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.