FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, ecamencodercompressh264 trusts server-controlled dimensions and does not validate the source buffer size, leading to an out-of-bounds read in swsscale. This vulnerability is fixed in 3.22.0.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/24xxx/CVE-2026-24677.json",
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-416"
]
}{
"cpe": "cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "3.22.0"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}[
{
"signature_type": "Line",
"signature_version": "v1",
"target": {
"file": "channels/remdesk/server/remdesk_main.c"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"302526760841945491736128439821008997434",
"70630154946512788056577155482393342922",
"226755686941808991255246028715889127531",
"213657514130521315432438747880543520493"
]
},
"source": "https://github.com/freerdp/freerdp/commit/d2d4f449312ddafd4a4c6c8a4f856c7f0d44a3b5",
"id": "CVE-2026-24677-1adf43a8"
},
{
"signature_type": "Function",
"signature_version": "v1",
"target": {
"file": "channels/rdpecam/client/camera_device_main.c",
"function": "ecam_dev_sample_captured_callback"
},
"deprecated": false,
"digest": {
"length": 1203.0,
"function_hash": "69747256394313293497778395012056896499"
},
"source": "https://github.com/freerdp/freerdp/commit/d2d4f449312ddafd4a4c6c8a4f856c7f0d44a3b5",
"id": "CVE-2026-24677-2c19cdc0"
},
{
"signature_type": "Function",
"signature_version": "v1",
"target": {
"file": "channels/rdpecam/client/camera_device_main.c",
"function": "ecam_dev_send_pending"
},
"deprecated": false,
"digest": {
"length": 943.0,
"function_hash": "90844528727004803234553406676805705492"
},
"source": "https://github.com/freerdp/freerdp/commit/d2d4f449312ddafd4a4c6c8a4f856c7f0d44a3b5",
"id": "CVE-2026-24677-34db2b64"
},
{
"signature_type": "Line",
"signature_version": "v1",
"target": {
"file": "channels/rdpecam/client/camera_device_main.c"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"76597263656988553479640259772101837929",
"24428191981771606167881920425381598871",
"29214146363746123862522431310743391998",
"182396834887074843693242073563823294427",
"154491812413754925618801079965824219791",
"336273421137499208786244914217470016783",
"273421504793331940674692714337030911358",
"317629935050515926784214234064225204631",
"218853314341058664231085366334068315718",
"273008287727771219302763501756043110439",
"48265817573017161355185623946165582241",
"301716846106156506063041874785141799776",
"151192390632738529748532344751095650157"
]
},
"source": "https://github.com/freerdp/freerdp/commit/d2d4f449312ddafd4a4c6c8a4f856c7f0d44a3b5",
"id": "CVE-2026-24677-456e4742"
},
{
"signature_type": "Function",
"signature_version": "v1",
"target": {
"file": "channels/rdpecam/client/encoding.c",
"function": "ecam_init_sws_context"
},
"deprecated": false,
"digest": {
"length": 902.0,
"function_hash": "244390137207550618994755807918965572227"
},
"source": "https://github.com/freerdp/freerdp/commit/d2d4f449312ddafd4a4c6c8a4f856c7f0d44a3b5",
"id": "CVE-2026-24677-c1aa3986"
},
{
"signature_type": "Line",
"signature_version": "v1",
"target": {
"file": "channels/rdpecam/client/camera.h"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"292203592307824299024520128129043922338",
"107596712014230612603911883536959801630",
"107376661428125199560340335926216911210"
]
},
"source": "https://github.com/freerdp/freerdp/commit/d2d4f449312ddafd4a4c6c8a4f856c7f0d44a3b5",
"id": "CVE-2026-24677-c81f89c0"
},
{
"signature_type": "Function",
"signature_version": "v1",
"target": {
"file": "channels/rdpecam/client/encoding.c",
"function": "ecam_encoder_compress_h264"
},
"deprecated": false,
"digest": {
"length": 2187.0,
"function_hash": "190743786932964571297532383142627310789"
},
"source": "https://github.com/freerdp/freerdp/commit/d2d4f449312ddafd4a4c6c8a4f856c7f0d44a3b5",
"id": "CVE-2026-24677-ce963931"
},
{
"signature_type": "Line",
"signature_version": "v1",
"target": {
"file": "channels/rdpecam/client/encoding.c"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"250863776580956012978145304419756292741",
"82503113705556099941551029093585705046",
"222398551432112162682536755392439750782",
"85850252031231641934628087409130885486",
"60388384044234459168117303097278998313",
"213260411857197646298729069628257893785",
"189594943875098197526258699142369325432",
"138999282537067161656823494220491750860",
"299971326695458478887500382186041295680",
"258447538846488556105378972124500157695",
"33380048272160696074829462005978295391",
"9784612275316316093724253752713103901",
"138154544085476027138021436029262749687",
"209893539047006002803543324338560703081",
"91383500476630301294427111536734453543",
"236620646187079544905386295256045454959",
"307260651721281656720592754218266298596",
"280276137413576242898563918247815353955",
"214599048608930937528386780969889699583",
"264220548132530715050351173223181736891",
"24472260660733766334336367953321083285",
"145245445128405290879852253721860067121",
"328051168706944005013744379892038666040",
"136962966061506588902048195581081912789"
]
},
"source": "https://github.com/freerdp/freerdp/commit/d2d4f449312ddafd4a4c6c8a4f856c7f0d44a3b5",
"id": "CVE-2026-24677-e244fe77"
},
{
"signature_type": "Function",
"signature_version": "v1",
"target": {
"file": "channels/rdpecam/client/encoding.c",
"function": "ecam_encoder_context_free_h264"
},
"deprecated": false,
"digest": {
"length": 662.0,
"function_hash": "85815799451564217972688120783115993518"
},
"source": "https://github.com/freerdp/freerdp/commit/d2d4f449312ddafd4a4c6c8a4f856c7f0d44a3b5",
"id": "CVE-2026-24677-ef12cf08"
},
{
"signature_type": "Function",
"signature_version": "v1",
"target": {
"file": "channels/remdesk/server/remdesk_main.c",
"function": "remdesk_server_thread"
},
"deprecated": false,
"digest": {
"length": 2216.0,
"function_hash": "339912793910049154183812692978068494150"
},
"source": "https://github.com/freerdp/freerdp/commit/d2d4f449312ddafd4a4c6c8a4f856c7f0d44a3b5",
"id": "CVE-2026-24677-f2d5d436"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-24677.json"
"2026-08-07T20:58:44Z"