CVE-2026-33982
published 2026-03-30CVE-2026-33982: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, there is a heap-buffer-overflow READ vulnerability at 24 bytes before…
PriorityP341high8.1CVSS 3.1
AVNACLPRNUIRSUCHINAH
EPSS
0.19%
9.0th percentile
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, there is a heap-buffer-overflow READ vulnerability at 24 bytes before the allocation, in winpr_aligned_offset_recalloc(). This issue has been patched in version 3.24.2.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | freerdp2 | < freerdp3 3.24.2+dfsg-1 (forky) | freerdp3 3.24.2+dfsg-1 (forky) |
| debian | freerdp3 | < freerdp3 3.24.2+dfsg-1 (forky) | freerdp3 3.24.2+dfsg-1 (forky) |
| freerdp | freerdp | < 3.24.2 | 3.24.2 |
| freerdp | freerdp | — | — |
| ubuntu | freerdp3 | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
osv8.1HIGH
vendor_redhat8.1HIGH
vendor_debian7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FreeRDP vulnerabilities
vendor_ubuntu·2026-07-20
CVE-2026-33995 FreeRDP vulnerabilities
Title: FreeRDP vulnerabilities
Summary: Several security issues were fixed in FreeRDP.
It was discovered that FreeRDP contained multiple security issues. An
attacker could possibly use these issues to obtain sensitive information,
cause FreeRDP to crash, resulting in a denial of service, or execute
arbitrary code.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
Red Hat
FreeRDP: FreeRDP: Information disclosure and denial of service via heap-buffer-overflow read
vendor_redhat·2026-03-30·CVSS 8.1
CVE-2026-33982 [HIGH] CWE-125 FreeRDP: FreeRDP: Information disclosure and denial of service via heap-buffer-overflow read
FreeRDP: FreeRDP: Information disclosure and denial of service via heap-buffer-overflow read
A flaw was found in FreeRDP, a free implementation of the Remote Desktop Protocol. This vulnerability, a heap-buffer-overflow read, exists in the `winpr_aligned_offset_recalloc()` function. A local attacker could exploit this flaw, with user interaction, to read sensitive information from memory, leading to information disclosure, or cause the application to crash, resulting in a denial of service.
Statement: Red Hat systems require user authentication in order to interact with FreeRDP binaries. Unauthenticated interaction is not possible in default configurations and so the risk posed by this flaw is slightly mitigated to Red hat customers.
Mitigation: Mitigation for this issue is either not av
Debian
CVE-2026-33982: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio...
vendor_debian·2026·CVSS 7.1
CVE-2026-33982 [HIGH] CVE-2026-33982: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio...
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, there is a heap-buffer-overflow READ vulnerability at 24 bytes before the allocation, in winpr_aligned_offset_recalloc(). This issue has been patched in version 3.24.2.
Scope: local
bookworm: open
bullseye: open
OSV
CVE-2026-33982: FreeRDP is a free implementation of the Remote Desktop Protocol
osv·2026-03-30·CVSS 8.1
CVE-2026-33982 [HIGH] CVE-2026-33982: FreeRDP is a free implementation of the Remote Desktop Protocol
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, there is a heap-buffer-overflow READ vulnerability at 24 bytes before the allocation, in winpr_aligned_offset_recalloc(). This issue has been patched in version 3.24.2.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-33982 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.1
CVE-2026-33982 [MEDIUM] CVE-2026-33982 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33982 :
NixOS vulnerability analysis and mitigation
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, there is a heap-buffer-overflow READ vulnerability at 24 bytes before the allocation, in winpr_aligned_offset_recalloc(). This issue has been patched in version 3.24.2.
Source : NVD
## 8.1
Score
Published March 30, 2026
Severity HIGH
CNA Score 7.1
Affected Technologies
NixOS
Wolfi
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
freerdp-libs-debuginfo
freerdp-server
Sources
NVD
Alpine 3.23, edge Severity HIGH Has Fix Added at: Mar 29, 2026
Chainguard Has F
Bugzilla
CVE-2026-33982 FreeRDP: FreeRDP: Information disclosure and denial of service via heap-buffer-overflow read
bugzilla·2026-03-30·CVSS 8.1
CVE-2026-33982 [HIGH] CVE-2026-33982 FreeRDP: FreeRDP: Information disclosure and denial of service via heap-buffer-overflow read
CVE-2026-33982 FreeRDP: FreeRDP: Information disclosure and denial of service via heap-buffer-overflow read
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, there is a heap-buffer-overflow READ vulnerability at 24 bytes before the allocation, in winpr_aligned_offset_recalloc(). This issue has been patched in version 3.24.2.
2026-03-30
Published