FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in resize_vbar_entry() in libfreerdp/codec/clear.c, vBarEntry->size is updated to vBarEntry->count before the winpr_aligned_recalloc() call. If realloc fails, size is inflated while pixels still points to the old, smaller buffer. On a subsequent call where count <= size (the inflated value), realloc is skipped. The caller then writes count * bpp bytes of attacker-controlled pixel data into the undersized buffer, causing a heap buffer overflow. This issue has been patched in version 3.24.2.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:8458 https://access.redhat.com/errata/RHSA-2026:8458
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:8457 https://access.redhat.com/errata/RHSA-2026:8457
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:8945 https://access.redhat.com/errata/RHSA-2026:8945
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:9656 https://access.redhat.com/errata/RHSA-2026:9656
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:10709 https://access.redhat.com/errata/RHSA-2026:10709
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2026:11332 https://access.redhat.com/errata/RHSA-2026:11332
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:11333 https://access.redhat.com/errata/RHSA-2026:11333
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:11336 https://access.redhat.com/errata/RHSA-2026:11336
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2026:11651 https://access.redhat.com/errata/RHSA-2026:11651
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:11649 https://access.redhat.com/errata/RHSA-2026:11649
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:12388 https://access.redhat.com/errata/RHSA-2026:12388
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:12359 https://access.redhat.com/errata/RHSA-2026:12359
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:19033 https://access.redhat.com/errata/RHSA-2026:19033
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:19349 https://access.redhat.com/errata/RHSA-2026:19349