Logo
vulnerabilityCVE-2026-33952
Name
CVE-2026-33952
Source
NVD ( link)Debian ( link)
Description
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, an unvalidated auth_length field read from the network triggers a WINPR_ASSERT() failure in rts_read_auth_verifier_no_checks(), causing any FreeRDP client connecting through a malicious RDP Gateway to crash with SIGABRT. This is a pre-authentication denial of service affecting all FreeRDP clients using RPC-over-HTTP gateway transport. The assertion is active in default release builds (WITH_VERBOSE_WINPR_ASSERT=ON). This issue has been patched in version 3.24.2.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
freerdp
Exploitable

Vulnerability Ratings#


6
CVSSv4
6.5
CVSSv31
6.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.11.8
Exploitable
buildroot
master
2.11.8
Exploitable
yocto
master
2.11.8
Exploitable
yocto
master
3.26.0
Not Affected
yocto
scarthgap
2.11.8
Exploitable
yocto
scarthgap
3.4.0
Patched

Resolved with patches#


freerdp3 (yocto:scarthgap)

#
Title
Author
Resolve
1
[core,gateway] Check rpcconn_common_hdr_t::auth_length is
Armin Novak <armin.novak@thincast.com>
CVE-2026-33952