[CLSA-2026:1786028144] freerdp: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-06 14:55:56 UTC
Description:
- CVE-2026-33983: fix undefined-behaviour shift and ~80 billion iteration loop (CPU denial of service) in the progressive codec; make progressive_rfx_quant_sub reject components where q1 < q2 instead of letting the BYTE subtraction underflow into a bogus numBits shift exponent, and fail the tile upgrade when it does - CVE-2026-33984: fix out-of-bounds heap write in the CLEAR codec; update CLEAR_VBAR_ENTRY::size only after the pixel buffer realloc succeeded, so a failed realloc can no longer leave an inflated size with the old, smaller buffer
Updated packages:
  • freerdp-2.1.1-5.el7_9.tuxcare.els25.x86_64.rpm
    sha:81b820e59a1cb6dae87443cee5a46504863a9f89cb46e7740288477bbb4eb8cd
  • freerdp-devel-2.1.1-5.el7_9.tuxcare.els25.i686.rpm
    sha:de9016dce51877cc7d9fa16ee5986466e0bbdcf1c3db03bb4bc36013e430267e
  • freerdp-devel-2.1.1-5.el7_9.tuxcare.els25.x86_64.rpm
    sha:69392a258904752205409b652f7759138aa0aa77a4bfb1e4a1a52d33d9e4df80
  • freerdp-libs-2.1.1-5.el7_9.tuxcare.els25.i686.rpm
    sha:3993159600eadae10e2577c2ca57ed432f6135ed01bd9c5acaa97be6ba57fa64
  • freerdp-libs-2.1.1-5.el7_9.tuxcare.els25.x86_64.rpm
    sha:a08ceedbb429e1dd57682e03158378494fd88661a72714e369fae9a916581866
  • libwinpr-2.1.1-5.el7_9.tuxcare.els25.i686.rpm
    sha:01bcc838352574f9eab8f629d8e9569df8a5cec6d7fb6edf4f37ff03a948150c
  • libwinpr-2.1.1-5.el7_9.tuxcare.els25.x86_64.rpm
    sha:0be55eaa48e7f1c47df6164a7c48bb6ffe54e3d55b023cc32ca2724a266929c7
  • libwinpr-devel-2.1.1-5.el7_9.tuxcare.els25.i686.rpm
    sha:5d055a73a04fc1ac5aabd272418c38d91c6e03001062d9a43ef90b3d5e2b72a4
  • libwinpr-devel-2.1.1-5.el7_9.tuxcare.els25.x86_64.rpm
    sha:15d9c1167aa132f20dc6197797884f112edfdc65eee301a323c48bd10110866f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.