Release date:
2026-08-06 14:55:56 UTC
Description:
- CVE-2026-33983: fix undefined-behaviour shift and ~80 billion iteration loop (CPU denial of service) in the progressive codec; make progressive_rfx_quant_sub reject components where q1 < q2 instead of letting the BYTE subtraction underflow into a bogus numBits shift exponent, and fail the tile upgrade when it does
- CVE-2026-33984: fix out-of-bounds heap write in the CLEAR codec; update CLEAR_VBAR_ENTRY::size only after the pixel buffer realloc succeeded, so a failed realloc can no longer leave an inflated size with the old, smaller buffer
Updated packages:
-
freerdp-2.1.1-5.el7_9.tuxcare.els25.x86_64.rpm
sha:81b820e59a1cb6dae87443cee5a46504863a9f89cb46e7740288477bbb4eb8cd
-
freerdp-devel-2.1.1-5.el7_9.tuxcare.els25.i686.rpm
sha:de9016dce51877cc7d9fa16ee5986466e0bbdcf1c3db03bb4bc36013e430267e
-
freerdp-devel-2.1.1-5.el7_9.tuxcare.els25.x86_64.rpm
sha:69392a258904752205409b652f7759138aa0aa77a4bfb1e4a1a52d33d9e4df80
-
freerdp-libs-2.1.1-5.el7_9.tuxcare.els25.i686.rpm
sha:3993159600eadae10e2577c2ca57ed432f6135ed01bd9c5acaa97be6ba57fa64
-
freerdp-libs-2.1.1-5.el7_9.tuxcare.els25.x86_64.rpm
sha:a08ceedbb429e1dd57682e03158378494fd88661a72714e369fae9a916581866
-
libwinpr-2.1.1-5.el7_9.tuxcare.els25.i686.rpm
sha:01bcc838352574f9eab8f629d8e9569df8a5cec6d7fb6edf4f37ff03a948150c
-
libwinpr-2.1.1-5.el7_9.tuxcare.els25.x86_64.rpm
sha:0be55eaa48e7f1c47df6164a7c48bb6ffe54e3d55b023cc32ca2724a266929c7
-
libwinpr-devel-2.1.1-5.el7_9.tuxcare.els25.i686.rpm
sha:5d055a73a04fc1ac5aabd272418c38d91c6e03001062d9a43ef90b3d5e2b72a4
-
libwinpr-devel-2.1.1-5.el7_9.tuxcare.els25.x86_64.rpm
sha:15d9c1167aa132f20dc6197797884f112edfdc65eee301a323c48bd10110866f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.