## This update for freerdp fixes the following issues Update to version 3.26.0: * CVE-2026-33982: heap-buffer-overflow READ vulnerability at 24 bytes before the allocation, in winpr_aligned_offset_recalloc() (bsc#1261222). * CVE-2026-33985: FreeRDP: Information disclosure via heap memory out of bounds read (bsc#1261217). * CVE-2026-33986: heap OOB write due to H.264 YUV buffer dimension desync (bsc#1261223). * CVE-2026-33987: heap OOB write due to persistent cache bmpSize desync (bsc#1261226). * CVE-2026-33995: double-free vulnerability in kerberos_AcceptSecurityContext() and kerberos_InitializeSecurityContextA() (bsc#1261227). * CVE-2026-40033: heap buffer overflow in `gdi_CacheToSurface` allows attackers to cause a denial of service or achieve remote execute code (bsc#1266317).
* bsc#1174200
* bsc#1261217
* bsc#1261222
* bsc#1261223
* bsc#1261226
* bsc#1261227
* bsc#1262743
* bsc#1266317
* bsc#1267008
* bsc#1267009
* bsc#1267010
* bsc#1267011
Cross-
* CVE-2026-33982
* CVE-2026-33985
* CVE-2026-33986
* CVE-2026-33987
* CVE-2026-33995
* CVE-2026-40033
* CVE-2026-40254
* CVE-2026-44420
* CVE-2026-44421
* CVE-2026-44422
* CVE-2026-45700
CVSS scores:
* CVE-2026-33982 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-33982 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
* CVE-2026-33982 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
* CVE-2026-33985 ( SUSE ): 5.9
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-33985 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:L
Get the latest Linux and open source security news straight to your inbox.