FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in persistentcachereadentryv3() in libfreerdp/cache/persistent.c, persistent->bmpSize is updated before winpralignedrecalloc(). If realloc fails, bmpSize is inflated while bmpData points to the old buffer. This issue has been patched in version 3.24.2.
{
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33987.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"fixed": "3.24.2"
}
],
"source": "AFFECTED_FIELD"
}
],
"cwe_ids": [
"CWE-122",
"CWE-131"
]
}"2026-07-21T23:32:08Z"
[
{
"target": {
"function": "persistent_cache_read_entry_v3",
"file": "libfreerdp/cache/persistent.c"
},
"id": "CVE-2026-33987-62f5ba09",
"digest": {
"function_hash": "58849993226555931899617891628358983411",
"length": 820.0
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/freerdp/freerdp/commit/1a890eb43492b5eb707cb3dd6fc908f696e8fc1c"
},
{
"target": {
"file": "libfreerdp/cache/persistent.c"
},
"id": "CVE-2026-33987-faf56e79",
"digest": {
"line_hashes": [
"144084934384106105920872457981353433934",
"252484022160513035315998983559827960592",
"80475519738261571471892685644252625415",
"120215690817063648745482991951086479253",
"283660500509183273599708544240430802885",
"111622323690931993230872939770812941841",
"284999338403165042300272883371066573313",
"100639442879197902970668115181337658042",
"132553429521796369032411175878856853722",
"267128613490396365009740424161732530253",
"331635876019041395468286895483750668562",
"265666975278017193830018786440831874747",
"201035385124278947501646915920142299613",
"50206377966656712332946526692353488670",
"69725854626787657515895215948089303242",
"168604599710556692462205224083263298979"
],
"threshold": 0.9
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/freerdp/freerdp/commit/1a890eb43492b5eb707cb3dd6fc908f696e8fc1c"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33987.json"