FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, progressivedecompresstileupgrade() detects a mismatch via progressiverfxquantcmpequal() but only emits WLogWARN, execution continues. The wrapped value (247) is used as a shift exponent, causing undefined behavior and an approximately 80 billion iteration loop (CPU DoS). This issue has been patched in version 3.24.2.
{
"cwe_ids": [
"CWE-190",
"CWE-252"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33983.json",
"cna_assigner": "GitHub_M",
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"fixed": "3.24.2"
}
]
}
]
}"2026-07-22T03:44:36Z"
[
{
"signature_type": "Line",
"target": {
"file": "libfreerdp/codec/progressive.c"
},
"deprecated": false,
"source": "https://github.com/freerdp/freerdp/commit/78188ab479c8e6eb9ba2475b3732c76b4bbe5425",
"id": "CVE-2026-33983-982c8937",
"signature_version": "v1",
"digest": {
"line_hashes": [
"93353622505111390641882887844937277427",
"233908802214677999810634991854501629448",
"279142864844677305642716569359495253629",
"77569140509167542282398447243129113926",
"83612844996024105248664012484422011615",
"49781137138012574405199941494173475843",
"303170522966309767556167581485631193903",
"117674432803128929237739529249738416465",
"258303796643107187888805234840245563928",
"95195163942263249254929860241644909034",
"324452841881576761841371846305693526061",
"241555397306320874230176152574148632892",
"2140984073463181123878284469717546140",
"189480764641963025008645612231610617666",
"106305128971618163191092944166443280406",
"228520105562675674535300842835957570250",
"161063130164877359825491039384325625507",
"334297928795778675320517208706143758436",
"150500399394966192148632850450000736927",
"153678473575359258165617762855493813694",
"243477012013887053847528246786644999596",
"252698890282748040335583485150070376558",
"38545011161204013379981560391934922925"
],
"threshold": 0.9
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33983.json"