FreeRDP: ClearCodec Glyph Cache Count Desync - Heap OOB Read
Published Mar 30, 2026
7.1
HIGHCVSS 3.1
EPSS 0.21%
Description
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, pixel data from adjacent heap memory is rendered to screen, potentially leaking sensitive data to the attacker. This issue has been patched in version 3.24.2.
Affected products
-
- Version < 3.24.2StatusaffectedConstraints-
- Version
No data.
Red Hat Enterprise Linux 10
freerdp-2:3.10.3-12.el10_2.5
Fixed · RHSA-2026:19142
Red Hat Enterprise Linux 10
freerdp-2:3.10.3-5.el10_1.8
Fixed · RHSA-2026:16014
Red Hat Enterprise Linux 10.0 Extended Update Support
freerdp-2:3.10.3-3.el10_0.7
Fixed · RHSA-2026:20605
Red Hat Enterprise Linux 7 Extended Lifecycle Support
freerdp-0:2.1.1-5.el7_9.9
Fixed · RHSA-2026:20546
Red Hat Enterprise Linux 8
freerdp-2:2.11.7-9.el8_10
Fixed · RHSA-2026:16019
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
freerdp-2:2.2.0-14.el8_4
Fixed · RHSA-2026:19811
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
freerdp-2:2.2.0-14.el8_4
Fixed · RHSA-2026:19811
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
freerdp-2:2.2.0-7.el8_6.8
Fixed · RHSA-2026:16814
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
freerdp-2:2.2.0-7.el8_6.8
Fixed · RHSA-2026:16814
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
freerdp-2:2.2.0-7.el8_6.8
Fixed · RHSA-2026:16814
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
freerdp-2:2.2.0-12.el8_8.8
Fixed · RHSA-2026:16777
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
freerdp-2:2.2.0-12.el8_8.8
Fixed · RHSA-2026:16777
Red Hat Enterprise Linux 9
freerdp-2:2.11.7-1.el9_7.7
Fixed · RHSA-2026:16482
Red Hat Enterprise Linux 9
freerdp-2:2.11.7-7.el9_8.3
Fixed · RHSA-2026:19358
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
freerdp-2:2.4.1-3.el9_0.7
Fixed · RHSA-2026:16485
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
freerdp-2:2.4.1-6.el9_2.9
Fixed · RHSA-2026:16483
Red Hat Enterprise Linux 9.4 Extended Update Support
freerdp-2:2.11.2-1.el9_4.8
Fixed · RHSA-2026:16866
Red Hat Enterprise Linux 9.6 Extended Update Support
freerdp-2:2.11.7-1.el9_6.10
Fixed · RHSA-2026:16865
Red Hat Enterprise Linux 6
freerdp
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | freerdp-2:3.10.3-12.el10_2.5 | Fixed | RHSA-2026:19142 |
| Red Hat Enterprise Linux 10 | freerdp-2:3.10.3-5.el10_1.8 | Fixed | RHSA-2026:16014 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | freerdp-2:3.10.3-3.el10_0.7 | Fixed | RHSA-2026:20605 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | freerdp-0:2.1.1-5.el7_9.9 | Fixed | RHSA-2026:20546 |
| Red Hat Enterprise Linux 8 | freerdp-2:2.11.7-9.el8_10 | Fixed | RHSA-2026:16019 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | freerdp-2:2.2.0-14.el8_4 | Fixed | RHSA-2026:19811 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | freerdp-2:2.2.0-14.el8_4 | Fixed | RHSA-2026:19811 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | freerdp-2:2.2.0-7.el8_6.8 | Fixed | RHSA-2026:16814 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | freerdp-2:2.2.0-7.el8_6.8 | Fixed | RHSA-2026:16814 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | freerdp-2:2.2.0-7.el8_6.8 | Fixed | RHSA-2026:16814 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | freerdp-2:2.2.0-12.el8_8.8 | Fixed | RHSA-2026:16777 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | freerdp-2:2.2.0-12.el8_8.8 | Fixed | RHSA-2026:16777 |
| Red Hat Enterprise Linux 9 | freerdp-2:2.11.7-1.el9_7.7 | Fixed | RHSA-2026:16482 |
| Red Hat Enterprise Linux 9 | freerdp-2:2.11.7-7.el9_8.3 | Fixed | RHSA-2026:19358 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | freerdp-2:2.4.1-3.el9_0.7 | Fixed | RHSA-2026:16485 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | freerdp-2:2.4.1-6.el9_2.9 | Fixed | RHSA-2026:16483 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | freerdp-2:2.11.2-1.el9_4.8 | Fixed | RHSA-2026:16866 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | freerdp-2:2.11.7-1.el9_6.10 | Fixed | RHSA-2026:16865 |
| Red Hat Enterprise Linux 6 | freerdp | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L
2 other sources (GitHub, Red Hat) ▾
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:L
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Mar 31, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
Mar-Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 0.21% (0.00205) | 9.45th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.21% (0.00205) | 10.46th | v5 (v2026.06.15) |
| Mar 31, 2026 | 0.04% (0.00038) | 11.38th | v4 (v2025.03.14) |
References (6)
- https://access.redhat.com/security/cve/CVE-2026-33985 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2453217 Issue Tracking
- https://github.com/FreeRDP/FreeRDP/commit/c49d1ad43b8c7b32794d0250f2623c2dccd7ef25 x_refsource_MISCPatch
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-x6gr-8p7h-5h85 x_refsource_CONFIRMPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-33985
- https://www.cve.org/CVERecord?id=CVE-2026-33985
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-33985 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2453217 | Issue Tracking | |
| https://github.com/FreeRDP/FreeRDP/commit/c49d1ad43b8c7b32794d0250f2623c2dccd7ef25 | x_refsource_MISCPatch | |
| https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-x6gr-8p7h-5h85 | x_refsource_CONFIRMPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-33985 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-33985 |
Change history (0)
No recorded changes yet.