[CLSA-2026:1786029097] freerdp: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-08 21:14:09 UTC
Description:
- CVE-2026-33983: fix undefined-behaviour shift and ~80 billion iteration loop (CPU denial of service) in the progressive codec; make progressive_rfx_quant_sub reject components where q1 < q2 instead of letting the BYTE subtraction underflow into a bogus numBits shift exponent, and fail the tile upgrade when it does - CVE-2026-33984: fix out-of-bounds heap write in the CLEAR codec; update CLEAR_VBAR_ENTRY::size only after the pixel buffer realloc succeeded, so a failed realloc can no longer leave an inflated size with the old, smaller buffer
Updated packages:
  • freerdp-2.1.1-5.el7_9.tuxcare.els25.x86_64.rpm
    sha:417959b0226c7d7303034faa3debff1a5062e22daf4a13fde6757e574c70be45
  • freerdp-devel-2.1.1-5.el7_9.tuxcare.els25.i686.rpm
    sha:8bf08bd2d04aac867c6368123f55f8f8cecd642dd223627ea7afb3d10f752f39
  • freerdp-devel-2.1.1-5.el7_9.tuxcare.els25.x86_64.rpm
    sha:cda1482c146ffd3bc23e6d24abb2563553d8fc10fada793575b1876e9c7370c5
  • freerdp-libs-2.1.1-5.el7_9.tuxcare.els25.i686.rpm
    sha:755d3472298163b5acf6d5f55d77ca66ca65e0fbcfb862e0f65cc3d74a872306
  • freerdp-libs-2.1.1-5.el7_9.tuxcare.els25.x86_64.rpm
    sha:2a125f7a985606f5dcb9208c52312640bb9e2dae243d04f729902b0ddf4761b2
  • libwinpr-2.1.1-5.el7_9.tuxcare.els25.i686.rpm
    sha:09aee870956b171ebbbf022a82780677c110ad0114348a055f3087857d346502
  • libwinpr-2.1.1-5.el7_9.tuxcare.els25.x86_64.rpm
    sha:820ea80acc3f7e25cc83e1a60dd5a28a838ed3c1adeeb9f8009a0efbdf89066d
  • libwinpr-devel-2.1.1-5.el7_9.tuxcare.els25.i686.rpm
    sha:0b7719ad2339e1b9fcdfa6455d638dce224eb44f77558c5d9949e5f127fd590f
  • libwinpr-devel-2.1.1-5.el7_9.tuxcare.els25.x86_64.rpm
    sha:96901ee47932ad59956fa34fe079bad161463ab4e526a7de1a4ef1fb4ccda607
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.