Opened 6 months ago

Closed 6 months ago

#23043 closed enhancement (fixed)

FreeRDP-3.24.2

Reported by: Bruce Dubbs Owned by: Douglas R. Reno
Priority: high Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (5)

comment:1 by Douglas R. Reno, 6 months ago

Priority: normal → high
CVE fixes

We got 4 High and 2 Moderate security reports from

    Calvin Young - eWalker Consulting
    Enoch Chow - Isomorph Cyber

and 2 Modreate reports from

    [Sebastian Alba Vives] @.***) Sebastián Alba

and 1 Moderate report from

    @prahal

CVE have been requested but not assigned yet. They will be published once assigned at 
https://github.com/FreeRDP/FreeRDP/security

What’s Changed

    [channels,video] fix wrong cast (#12511)
    [codec,openh264] reject encoder ABI mismatch on runtime-loaded library (#12510)
    [client,sdl] create a copy of rdpPointer (#12512)
    [codec,video] properly pass intermediate format (#12518)
    [utils, signal] lazily initialize Windows CRITICAL_SECTION to match POSIX static 
mutex behavior (#12520)
    winpr: improve libunwind backtraces (#12530)
    [server,shadow] remember selected caps (#12528)
    Zero credential data before free in NLA and NTLM context (#12532)
    [server,proxy] ignore missing client in input channel (#12536)
    [server,proxy] ignore rdpdr messages (#12537)
    [winpr,sspi] improve kerberos logging (#12538)
    Codec fixes (#12542)

Did someone say... more security updates? :(

comment:2 by Douglas R. Reno, 6 months ago

Owner: changed from blfs-book to Douglas R. Reno
Status: new → assigned

comment:3 by Douglas R. Reno, 6 months ago

Security Information:

  • CVE-2026-33952 (Medium): DoS via WINPR_ASSERT in rts_read_auth_verifier_no_checks (rts.c:282)
  • CVE-2026-33977 (Medium): DoS via WINPR_ASSERT in IMA ADPCM audio decoder (dsp.c:331)
  • CVE-2026-33995 (Medium): double free in kerberos_AcceptSecurityContext and kerberos_IntitalizeSecurityContextA
  • CVE-2026-33984 (High): ClearCodec resize_vbar_entry() Heap OOB Write
  • CVE-2026-33983 (Medium): Progressive Codec Quant BYTE Underflow - UB + CPU DoS
  • CVE-2026-33985 (Medium): ClearCodec Glyph Cache Count Desync - Heap OOB Read
  • CVE-2026-33986 (High): H.264 YUV Buffer Dimension Desync - Heap OOB Write On a brief scan, this one concerns me. 33MB heap overflow, attacker controlled! This can get triggered just by connecting to a Windows Server 2012 / Windows 8.0 system or later.
  • CVE-2026-33987 (High): Persistent Cache bmpSize Desync - Heap OOB Write
  • CVE-2026-33982 (High): Persistent Cache Allocator Mismatch - Heap OOB Read

comment:4 by Douglas R. Reno, 6 months ago

Fixed at 237c48068f8e2a3be8f483ad099a2e65fa164c0a

SA pending until I have KF6 building.

comment:5 by Douglas R. Reno, 6 months ago

Resolution: → fixed
Status: assigned → closed

SA-13.0-031 issued

Note: See TracTickets for help on using tickets.