CVE-2026-29774Disclosure(freerdp / freerdp)

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a client-side heap buffer overflow occurs in the FreeRDP client's AVC420/AVC444 YUV-to-RGB conversion path due to missing horizontal bounds validation of H.264 metablock regionRects coordinates. In yuv.c, the clamp() function (line 347) only validates top/bottom against the surface/YUV height, but never checks left/right against the surface width. When avc420_yuv_to_rgb (line 67) computes destination and source pointers using rect->left, it performs unchecked pointer arithmetic that can reach far beyond the allocated surface buffer. A malicious server sends a WIRE_TO_SURFACE_PDU_1 with AVC420 codec containing a regionRects entry where left greatly exceeds the surface width (e.g., left=60000 on a 128px surface). The H.264 bitstream decodes successfully, then yuv420_process_work_callback calls avc420_yuv_to_rgb which computes pDstPoint = pDstData + rect->top * nDstStep + rect->left * 4, writing 16-byte SSE vectors 1888+ bytes past the allocated heap region. This vulnerability is fixed in 3.24.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freerdp

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-13); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
freerdp

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-13: 3Mentions · 2026-05-13: 1Technical Details · 2026-03-13: 3Technical Details · 2026-05-13: 103-1305-13
Signal classification1 categories
Disclosure
4100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-133
Disclosure3
2026-05-131
Disclosure1
Full discourse4 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    Three CVEs (CVE-2026-29774, CVE-2026-30015, CVE-2026-30221) exploited the fact that the protocol did not, in version 1.2, canonicalize tool names. Multiple servers in the same session could expose tools named, respectively: readfile (the legitimate filesystem server)…

    Post summary

    Three CVEs target a version‑1.2 protocol flaw that fails to canonicalize tool names, exposing servers such as readfile; technical details are given but no PoC, patch, or active exploitation is reported.

    1000033
    210 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-29774 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a client-side heap buffer overflow occurs in the FreeRDP client's AVC420/AVC444 YUV-… https://www.cve.org/CVERecord?id=CVE-2026-29774 ----- Traducción: CVE-2026-29774 Fre… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑29774, detailing a client‑side heap buffer overflow in FreeRDP prior to version 3.24.0, and links to the official CVE record.

    0000032
    57 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-29774 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a client-side heap buffer overflow occurs in the FreeRDP client's AVC420/AVC444 YUV-… https://www.cve.org/CVERecord?id=CVE-2026-29774

    Post summary

    The text announces a client‑side heap buffer overflow in FreeRDP before version 3.24.0, providing technical details without evidence of exploitation or mitigation.

    00000336
    56.7K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-29774 - FreeRDP Heap Buffer Overflow Vulnerability Intel Report: https://ift.tt/QW9e4oR

    Post summary

    The alert announces the discovery of a FreeRDP heap buffer overflow (CVE-2026-29774) and links to an Intel report, but does not provide exploitation details, PoC, or patch information.

    0000026
    340 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfreerdpfreerdp---

Explore more