Reachable assertion in FreeRDP - CVE-2026-33952
Published: April 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to reachable assertion in rts_read_auth_verifier_no_checks() in libfreerdp/core/gateway/rts.c when processing RPC-over-HTTP gateway PDUs. A remote attacker can send a specially crafted PDU with an invalid auth_length field to cause a denial of service.
The issue is reachable during connection setup before authentication and affects clients using RDP Gateway transport.
Affected software
Fedora
freerdp
How to mitigate CVE-2026-33952
freerdp - addressed in versions 3.24.2-1.fc42, 3.24.2-1.fc43, 3.24.2-1.fc44