Bug 2453220 (CVE-2026-33983)

Summary: CVE-2026-33983 FreeRDP: FreeRDP: Denial of Service via specially crafted Remote Desktop Protocol messages
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in FreeRDP, a free implementation of the Remote Desktop Protocol (RDP). A remote attacker could exploit this vulnerability by sending a specially crafted RDP message. This can lead to an undefined behavior where a wrapped value is used as a shift exponent, causing an approximately 80 billion iteration loop. This results in a Denial of Service (DoS) due to excessive CPU utilization.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2453238, 2453240, 2453239    
Bug Blocks:    

Description OSIDB Bzimport 2026-03-30 22:01:53 UTC
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, progressive_decompress_tile_upgrade() detects a mismatch via progressive_rfx_quant_cmp_equal() but only emits WLog_WARN, execution continues. The wrapped value (247) is used as a shift exponent, causing undefined behavior and an approximately 80 billion iteration loop (CPU DoS). This issue has been patched in version 3.24.2.

Comment 2 errata-xmlrpc 2026-04-16 12:45:13 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:8458 https://access.redhat.com/errata/RHSA-2026:8458

Comment 3 errata-xmlrpc 2026-04-16 13:12:34 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:8457 https://access.redhat.com/errata/RHSA-2026:8457

Comment 4 errata-xmlrpc 2026-04-20 11:21:22 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:8945 https://access.redhat.com/errata/RHSA-2026:8945

Comment 5 errata-xmlrpc 2026-04-22 09:37:05 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:9656 https://access.redhat.com/errata/RHSA-2026:9656

Comment 6 errata-xmlrpc 2026-04-27 02:05:59 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2026:10709 https://access.redhat.com/errata/RHSA-2026:10709

Comment 7 errata-xmlrpc 2026-04-28 07:36:30 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2026:11332 https://access.redhat.com/errata/RHSA-2026:11332

Comment 8 errata-xmlrpc 2026-04-28 07:37:49 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:11333 https://access.redhat.com/errata/RHSA-2026:11333

Comment 9 errata-xmlrpc 2026-04-28 07:48:26 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:11336 https://access.redhat.com/errata/RHSA-2026:11336

Comment 10 errata-xmlrpc 2026-04-29 11:25:20 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Advanced Update Support

Via RHSA-2026:11651 https://access.redhat.com/errata/RHSA-2026:11651

Comment 11 errata-xmlrpc 2026-04-29 11:28:25 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:11649 https://access.redhat.com/errata/RHSA-2026:11649

Comment 12 errata-xmlrpc 2026-04-30 16:48:42 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service

Via RHSA-2026:12388 https://access.redhat.com/errata/RHSA-2026:12388

Comment 13 errata-xmlrpc 2026-04-30 17:49:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:12359 https://access.redhat.com/errata/RHSA-2026:12359

Comment 14 errata-xmlrpc 2026-05-19 13:05:28 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:19033 https://access.redhat.com/errata/RHSA-2026:19033

Comment 15 errata-xmlrpc 2026-05-19 21:37:28 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:19349 https://access.redhat.com/errata/RHSA-2026:19349