CVE-2026-33986: Freerdp
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in yuv_ensure_buffer() in libfreerdp/codec/h264.c, h264->width and h264->height are updated before the reallocation loop. If any winpr_aligned_recalloc() call fails, the function returns FALSE but width/height are already inflated. This issue has been patched in version 3.24.2.
Affected products
- Freerdp Freerdp: before 3.24.2 (fixed in 3.24.2)
Published 2026-03-30. Last modified 2026-07-15.