CVE-2026-24677

Source
https://cve.org/CVERecord?id=CVE-2026-24677
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-24677.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-24677
Aliases
  • GHSA-xw37-j744-f8v7
Downstream
Related
Published
2026-02-09T18:16:44.715Z
Modified
2026-08-07T20:58:44.018644Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
FreeRDP has a heap-buffer-overflow in ecam_encoder_compress_h264
Details

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, ecamencodercompressh264 trusts server-controlled dimensions and does not validate the source buffer size, leading to an out-of-bounds read in swsscale. This vulnerability is fixed in 3.22.0.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/24xxx/CVE-2026-24677.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-416"
    ]
}
References

Affected packages

Git / github.com/freerdp/freerdp

Affected ranges

Type
GIT
Repo
https://github.com/freerdp/freerdp
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
{
    "cpe": "cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "3.22.0"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.0-beta1
1.0-beta2
1.0-beta4
1.0-beta5
1.0.0
1.0.1
1.1.0-beta+2013071101
1.1.0-beta1
1.1.0-beta1+android2
1.1.0-beta1+android3
1.1.0-beta1+android4
1.1.0-beta1+android5
1.1.0-beta1+ios1
1.1.0-beta1+ios2
1.1.0-beta1+ios3
1.1.0-beta1+ios4
1.2.0-beta1+android7
1.2.0-beta1+android9
2.*
2.0.0
2.0.0-beta1+android10
2.0.0-beta1+android11
2.0.0-rc0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
3.*
3.0.0
3.0.0-beta1
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-rc0
3.1.0
3.2.0
3.3.0
3.4.0
3.5.0
3.5.1

Database specific

vanir_signatures
[
    {
        "signature_type": "Line",
        "signature_version": "v1",
        "target": {
            "file": "channels/remdesk/server/remdesk_main.c"
        },
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "302526760841945491736128439821008997434",
                "70630154946512788056577155482393342922",
                "226755686941808991255246028715889127531",
                "213657514130521315432438747880543520493"
            ]
        },
        "source": "https://github.com/freerdp/freerdp/commit/d2d4f449312ddafd4a4c6c8a4f856c7f0d44a3b5",
        "id": "CVE-2026-24677-1adf43a8"
    },
    {
        "signature_type": "Function",
        "signature_version": "v1",
        "target": {
            "file": "channels/rdpecam/client/camera_device_main.c",
            "function": "ecam_dev_sample_captured_callback"
        },
        "deprecated": false,
        "digest": {
            "length": 1203.0,
            "function_hash": "69747256394313293497778395012056896499"
        },
        "source": "https://github.com/freerdp/freerdp/commit/d2d4f449312ddafd4a4c6c8a4f856c7f0d44a3b5",
        "id": "CVE-2026-24677-2c19cdc0"
    },
    {
        "signature_type": "Function",
        "signature_version": "v1",
        "target": {
            "file": "channels/rdpecam/client/camera_device_main.c",
            "function": "ecam_dev_send_pending"
        },
        "deprecated": false,
        "digest": {
            "length": 943.0,
            "function_hash": "90844528727004803234553406676805705492"
        },
        "source": "https://github.com/freerdp/freerdp/commit/d2d4f449312ddafd4a4c6c8a4f856c7f0d44a3b5",
        "id": "CVE-2026-24677-34db2b64"
    },
    {
        "signature_type": "Line",
        "signature_version": "v1",
        "target": {
            "file": "channels/rdpecam/client/camera_device_main.c"
        },
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "76597263656988553479640259772101837929",
                "24428191981771606167881920425381598871",
                "29214146363746123862522431310743391998",
                "182396834887074843693242073563823294427",
                "154491812413754925618801079965824219791",
                "336273421137499208786244914217470016783",
                "273421504793331940674692714337030911358",
                "317629935050515926784214234064225204631",
                "218853314341058664231085366334068315718",
                "273008287727771219302763501756043110439",
                "48265817573017161355185623946165582241",
                "301716846106156506063041874785141799776",
                "151192390632738529748532344751095650157"
            ]
        },
        "source": "https://github.com/freerdp/freerdp/commit/d2d4f449312ddafd4a4c6c8a4f856c7f0d44a3b5",
        "id": "CVE-2026-24677-456e4742"
    },
    {
        "signature_type": "Function",
        "signature_version": "v1",
        "target": {
            "file": "channels/rdpecam/client/encoding.c",
            "function": "ecam_init_sws_context"
        },
        "deprecated": false,
        "digest": {
            "length": 902.0,
            "function_hash": "244390137207550618994755807918965572227"
        },
        "source": "https://github.com/freerdp/freerdp/commit/d2d4f449312ddafd4a4c6c8a4f856c7f0d44a3b5",
        "id": "CVE-2026-24677-c1aa3986"
    },
    {
        "signature_type": "Line",
        "signature_version": "v1",
        "target": {
            "file": "channels/rdpecam/client/camera.h"
        },
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "292203592307824299024520128129043922338",
                "107596712014230612603911883536959801630",
                "107376661428125199560340335926216911210"
            ]
        },
        "source": "https://github.com/freerdp/freerdp/commit/d2d4f449312ddafd4a4c6c8a4f856c7f0d44a3b5",
        "id": "CVE-2026-24677-c81f89c0"
    },
    {
        "signature_type": "Function",
        "signature_version": "v1",
        "target": {
            "file": "channels/rdpecam/client/encoding.c",
            "function": "ecam_encoder_compress_h264"
        },
        "deprecated": false,
        "digest": {
            "length": 2187.0,
            "function_hash": "190743786932964571297532383142627310789"
        },
        "source": "https://github.com/freerdp/freerdp/commit/d2d4f449312ddafd4a4c6c8a4f856c7f0d44a3b5",
        "id": "CVE-2026-24677-ce963931"
    },
    {
        "signature_type": "Line",
        "signature_version": "v1",
        "target": {
            "file": "channels/rdpecam/client/encoding.c"
        },
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "250863776580956012978145304419756292741",
                "82503113705556099941551029093585705046",
                "222398551432112162682536755392439750782",
                "85850252031231641934628087409130885486",
                "60388384044234459168117303097278998313",
                "213260411857197646298729069628257893785",
                "189594943875098197526258699142369325432",
                "138999282537067161656823494220491750860",
                "299971326695458478887500382186041295680",
                "258447538846488556105378972124500157695",
                "33380048272160696074829462005978295391",
                "9784612275316316093724253752713103901",
                "138154544085476027138021436029262749687",
                "209893539047006002803543324338560703081",
                "91383500476630301294427111536734453543",
                "236620646187079544905386295256045454959",
                "307260651721281656720592754218266298596",
                "280276137413576242898563918247815353955",
                "214599048608930937528386780969889699583",
                "264220548132530715050351173223181736891",
                "24472260660733766334336367953321083285",
                "145245445128405290879852253721860067121",
                "328051168706944005013744379892038666040",
                "136962966061506588902048195581081912789"
            ]
        },
        "source": "https://github.com/freerdp/freerdp/commit/d2d4f449312ddafd4a4c6c8a4f856c7f0d44a3b5",
        "id": "CVE-2026-24677-e244fe77"
    },
    {
        "signature_type": "Function",
        "signature_version": "v1",
        "target": {
            "file": "channels/rdpecam/client/encoding.c",
            "function": "ecam_encoder_context_free_h264"
        },
        "deprecated": false,
        "digest": {
            "length": 662.0,
            "function_hash": "85815799451564217972688120783115993518"
        },
        "source": "https://github.com/freerdp/freerdp/commit/d2d4f449312ddafd4a4c6c8a4f856c7f0d44a3b5",
        "id": "CVE-2026-24677-ef12cf08"
    },
    {
        "signature_type": "Function",
        "signature_version": "v1",
        "target": {
            "file": "channels/remdesk/server/remdesk_main.c",
            "function": "remdesk_server_thread"
        },
        "deprecated": false,
        "digest": {
            "length": 2216.0,
            "function_hash": "339912793910049154183812692978068494150"
        },
        "source": "https://github.com/freerdp/freerdp/commit/d2d4f449312ddafd4a4c6c8a4f856c7f0d44a3b5",
        "id": "CVE-2026-24677-f2d5d436"
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-24677.json"
vanir_signatures_modified
"2026-08-07T20:58:44Z"