FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, there is a heap-buffer-overflow READ vulnerability at 24 bytes before the allocation, in winpralignedoffset_recalloc(). This issue has been patched in version 3.24.2.
{
"cwe_ids": [
"CWE-125"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33982.json",
"cna_assigner": "GitHub_M",
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"fixed": "3.24.2"
}
]
}
]
}"2026-07-22T00:02:54Z"
[
{
"signature_type": "Function",
"target": {
"file": "libfreerdp/cache/persistent.c",
"function": "persistent_cache_read_entry_v3"
},
"deprecated": false,
"source": "https://github.com/freerdp/freerdp/commit/a48dbde2c8a5b8b70a9d1c045d969a71afd6284c",
"id": "CVE-2026-33982-130a38c8",
"signature_version": "v1",
"digest": {
"function_hash": "320394113324326461490117516650226532276",
"length": 814.0
}
},
{
"signature_type": "Function",
"target": {
"file": "libfreerdp/cache/persistent.c",
"function": "persistent_cache_new"
},
"deprecated": false,
"source": "https://github.com/freerdp/freerdp/commit/a48dbde2c8a5b8b70a9d1c045d969a71afd6284c",
"id": "CVE-2026-33982-50dede54",
"signature_version": "v1",
"digest": {
"function_hash": "339680760945305690578763630665798340834",
"length": 264.0
}
},
{
"signature_type": "Line",
"target": {
"file": "libfreerdp/cache/persistent.c"
},
"deprecated": false,
"source": "https://github.com/freerdp/freerdp/commit/a48dbde2c8a5b8b70a9d1c045d969a71afd6284c",
"id": "CVE-2026-33982-899b8aed",
"signature_version": "v1",
"digest": {
"line_hashes": [
"283775200926530570219154730823401869481",
"104676554167316622436203919072443547966",
"241137310166181725429755143254380870828",
"55735469161518424490925210403296052826",
"329218132929044373822586384957449481447",
"69831361137629150205098205416833647936",
"107530161213400617767865586613897339881",
"336930435126234267483162636910829119317",
"132383995117502571618269692280110021575",
"114439756357433356701750770555477000437",
"292780370065535459505732074315227931285"
],
"threshold": 0.9
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33982.json"