#VU125368 Out-of-bounds read in FreeRDP - CVE-2026-33985
Published: April 8, 2026
FreeRDP
FreeRDP
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in clear_decompress_glyph_data() in libfreerdp/codec/clear.c when processing a subsequent CLEARCODEC_FLAG_GLYPH_HIT call after a failed winpr_aligned_recalloc() operation. A remote attacker can send specially crafted ClearCodec glyph data to disclose sensitive information.
Pixel data from adjacent heap memory may be rendered to the screen. User interaction is required.