CVE-2026-33982
HIGHFreeRDP: Persistent Cache Allocator Mismatch - Heap OOB Read
Title source: cnaDescription
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, there is a heap-buffer-overflow READ vulnerability at 24 bytes before the allocation, in winpr_aligned_offset_recalloc(). This issue has been patched in version 3.24.2.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-8jm9-2925-g4v2
X_Refsource_Misc x_refsource_misc
https://github.com/FreeRDP/FreeRDP/commit/a48dbde2c8a5b8b70a9d1c045d969a71afd6284c
Scores
CVSS v3
7.1
EPSS
0.0019
EPSS Percentile
8.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-125
Status
published
Products (2)
freerdp/freerdp
< 3.24.2
FreeRDP/FreeRDP
< 3.24.2
Published
Mar 30, 2026
Tracked Since
Mar 31, 2026