Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33982

Опубликовано: 30 мар. 2026
Источник: redhat
CVSS3: 6.6
EPSS Низкий

Описание

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, there is a heap-buffer-overflow READ vulnerability at 24 bytes before the allocation, in winpr_aligned_offset_recalloc(). This issue has been patched in version 3.24.2.

A flaw was found in FreeRDP, a free implementation of the Remote Desktop Protocol. This vulnerability, a heap-buffer-overflow read, exists in the winpr_aligned_offset_recalloc() function. A local attacker could exploit this flaw, with user interaction, to read sensitive information from memory, leading to information disclosure, or cause the application to crash, resulting in a denial of service.

Отчет

Red Hat systems require user authentication in order to interact with FreeRDP binaries. Unauthenticated interaction is not possible in default configurations and so the risk posed by this flaw is slightly mitigated to Red hat customers.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6freerdpOut of support scope
Red Hat Enterprise Linux 7freerdpOut of support scope
Red Hat Enterprise Linux 8freerdpNot affected
Red Hat Enterprise Linux 9freerdpNot affected
Red Hat Enterprise Linux 10freerdpFixedRHSA-2026:1601411.05.2026
Red Hat Enterprise Linux 10freerdpFixedRHSA-2026:1914219.05.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportfreerdpFixedRHSA-2026:2060526.05.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2453218FreeRDP: FreeRDP: Information disclosure and denial of service via heap-buffer-overflow read

EPSS

Процентиль: 9%
0.00191
Низкий

6.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
4 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, there is a heap-buffer-overflow READ vulnerability at 24 bytes before the allocation, in winpr_aligned_offset_recalloc(). This issue has been patched in version 3.24.2.

CVSS3: 7.1
nvd
4 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, there is a heap-buffer-overflow READ vulnerability at 24 bytes before the allocation, in winpr_aligned_offset_recalloc(). This issue has been patched in version 3.24.2.

CVSS3: 7.1
debian
4 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

CVSS3: 8.1
fstec
4 месяца назад

Уязвимость RDP-клиента FreeRDP, связанная с чтением за границами буфера в памяти, позволяющая нарушителю оказать воздействие на конфиденциальность и доступность защищаемой информации

CVSS3: 8.1
redos
около 2 месяцев назад

Уязвимость freerdp3

EPSS

Процентиль: 9%
0.00191
Низкий

6.6 Medium

CVSS3