CVE-2026-24677

Source
https://cve.org/CVERecord?id=CVE-2026-24677
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-24677.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-24677
Aliases
  • GHSA-xw37-j744-f8v7
Downstream
Related
Published
2026-02-09T18:16:44Z
Modified
2026-08-18T18:38:31Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
FreeRDP has a heap-buffer-overflow in ecam_encoder_compress_h264
Details

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, ecam_encoder_compress_h264 trusts server-controlled dimensions and does not validate the source buffer size, leading to an out-of-bounds read in sws_scale. This vulnerability is fixed in 3.22.0.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-416"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/24xxx/CVE-2026-24677.json"
}
References

Affected packages

Git / github.com/freerdp/freerdp

Affected ranges

Type
GIT
Repo
https://github.com/freerdp/freerdp
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "3.22.0"
        }
    ],
    "source":  [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.0-beta1
1.0-beta2
1.0-beta4
1.0-beta5
1.0.0
1.0.1
1.1.0-beta+2013071101
1.1.0-beta1
1.1.0-beta1+android2
1.1.0-beta1+android3
1.1.0-beta1+android4
1.1.0-beta1+android5
1.1.0-beta1+ios1
1.1.0-beta1+ios2
1.1.0-beta1+ios3
1.1.0-beta1+ios4
1.2.0-beta1+android7
1.2.0-beta1+android9
2.*
2.0.0
2.0.0-beta1+android10
2.0.0-beta1+android11
2.0.0-rc0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
3.*
3.0.0
3.0.0-beta1
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.0-rc0
3.1.0
3.2.0
3.3.0
3.4.0
3.5.0
3.5.1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-24677.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "302526760841945491736128439821008997434",
                "70630154946512788056577155482393342922",
                "226755686941808991255246028715889127531",
                "213657514130521315432438747880543520493"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-24677-1adf43a8",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/freerdp/freerdp/commit/d2d4f449312ddafd4a4c6c8a4f856c7f0d44a3b5",
        "target":  {
            "file":  "channels/remdesk/server/remdesk_main.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "69747256394313293497778395012056896499",
            "length":  1203
        },
        "id":  "CVE-2026-24677-2c19cdc0",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/freerdp/freerdp/commit/d2d4f449312ddafd4a4c6c8a4f856c7f0d44a3b5",
        "target":  {
            "file":  "channels/rdpecam/client/camera_device_main.c",
            "function":  "ecam_dev_sample_captured_callback"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "90844528727004803234553406676805705492",
            "length":  943
        },
        "id":  "CVE-2026-24677-34db2b64",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/freerdp/freerdp/commit/d2d4f449312ddafd4a4c6c8a4f856c7f0d44a3b5",
        "target":  {
            "file":  "channels/rdpecam/client/camera_device_main.c",
            "function":  "ecam_dev_send_pending"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "76597263656988553479640259772101837929",
                "24428191981771606167881920425381598871",
                "29214146363746123862522431310743391998",
                "182396834887074843693242073563823294427",
                "154491812413754925618801079965824219791",
                "336273421137499208786244914217470016783",
                "273421504793331940674692714337030911358",
                "317629935050515926784214234064225204631",
                "218853314341058664231085366334068315718",
                "273008287727771219302763501756043110439",
                "48265817573017161355185623946165582241",
                "301716846106156506063041874785141799776",
                "151192390632738529748532344751095650157"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-24677-456e4742",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/freerdp/freerdp/commit/d2d4f449312ddafd4a4c6c8a4f856c7f0d44a3b5",
        "target":  {
            "file":  "channels/rdpecam/client/camera_device_main.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "244390137207550618994755807918965572227",
            "length":  902
        },
        "id":  "CVE-2026-24677-c1aa3986",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/freerdp/freerdp/commit/d2d4f449312ddafd4a4c6c8a4f856c7f0d44a3b5",
        "target":  {
            "file":  "channels/rdpecam/client/encoding.c",
            "function":  "ecam_init_sws_context"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "292203592307824299024520128129043922338",
                "107596712014230612603911883536959801630",
                "107376661428125199560340335926216911210"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-24677-c81f89c0",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/freerdp/freerdp/commit/d2d4f449312ddafd4a4c6c8a4f856c7f0d44a3b5",
        "target":  {
            "file":  "channels/rdpecam/client/camera.h"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "190743786932964571297532383142627310789",
            "length":  2187
        },
        "id":  "CVE-2026-24677-ce963931",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/freerdp/freerdp/commit/d2d4f449312ddafd4a4c6c8a4f856c7f0d44a3b5",
        "target":  {
            "file":  "channels/rdpecam/client/encoding.c",
            "function":  "ecam_encoder_compress_h264"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "250863776580956012978145304419756292741",
                "82503113705556099941551029093585705046",
                "222398551432112162682536755392439750782",
                "85850252031231641934628087409130885486",
                "60388384044234459168117303097278998313",
                "213260411857197646298729069628257893785",
                "189594943875098197526258699142369325432",
                "138999282537067161656823494220491750860",
                "299971326695458478887500382186041295680",
                "258447538846488556105378972124500157695",
                "33380048272160696074829462005978295391",
                "9784612275316316093724253752713103901",
                "138154544085476027138021436029262749687",
                "209893539047006002803543324338560703081",
                "91383500476630301294427111536734453543",
                "236620646187079544905386295256045454959",
                "307260651721281656720592754218266298596",
                "280276137413576242898563918247815353955",
                "214599048608930937528386780969889699583",
                "264220548132530715050351173223181736891",
                "24472260660733766334336367953321083285",
                "145245445128405290879852253721860067121",
                "328051168706944005013744379892038666040",
                "136962966061506588902048195581081912789"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-24677-e244fe77",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/freerdp/freerdp/commit/d2d4f449312ddafd4a4c6c8a4f856c7f0d44a3b5",
        "target":  {
            "file":  "channels/rdpecam/client/encoding.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "85815799451564217972688120783115993518",
            "length":  662
        },
        "id":  "CVE-2026-24677-ef12cf08",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/freerdp/freerdp/commit/d2d4f449312ddafd4a4c6c8a4f856c7f0d44a3b5",
        "target":  {
            "file":  "channels/rdpecam/client/encoding.c",
            "function":  "ecam_encoder_context_free_h264"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "339912793910049154183812692978068494150",
            "length":  2216
        },
        "id":  "CVE-2026-24677-f2d5d436",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/freerdp/freerdp/commit/d2d4f449312ddafd4a4c6c8a4f856c7f0d44a3b5",
        "target":  {
            "file":  "channels/remdesk/server/remdesk_main.c",
            "function":  "remdesk_server_thread"
        }
    }
]
vanir_signatures_modified
"2026-08-18T18:38:31Z"