buildroot ▾
›
2025.02.x ▾
›
vulnerability
›
CVE-2026-29776
Component Overview
Vulnerability Overview
Name
CVE-2026-29776
Source
NVD (
link
)
Debian (
link
)
Description
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, Integer Underflow in update_read_cache_bitmap_order Function of FreeRDP's Core Library This vulnerability is fixed in 3.24.0.
CWEs
CWE-190
Published Date
Mar 13, 2026
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/FreeRDP/FreeRDP/commit/a9e0abf2eac8c2e370fa155bf1abb9d044c0ca8a
Patch
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-c747-x4wf-cqrr
Patch
Analysis
#
Affected Component
Analysis
freerdp
Exploitable
Vulnerability Ratings
#
3.1
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
freerdp
buildroot
master
2.11.8
Exploitable
freerdp
yocto
kirkstone
2.6.1
Exploitable
freerdp
yocto
master
2.11.8
Exploitable
freerdp3
yocto
master
3.26.0
Not Affected
freerdp
yocto
scarthgap
2.11.8
Exploitable
freerdp3
yocto
scarthgap
3.4.0
Patched
Resolved with patches
#
freerdp3 (yocto:scarthgap)
#
Title
Author
Resolve
1
[core,orders] improve input validation
Armin Novak <armin.novak@thincast.com>
CVE-2026-29776