PT-2026-29141 · Samba+4 · Samba+4

·

CVE-2026-33995

·

Published

2026-01-01

·

Updated

2026-08-10

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.24.2
Description FreeRDP is a free implementation of the Remote Desktop Protocol. A double-free issue exists in the kerberos AcceptSecurityContext() and kerberos InitializeSecurityContextA() functions (WinPR, winpr/libwinpr/sspi/Kerberos/kerberos.c). This can lead to a crash in FreeRDP clients on systems configured with Kerberos and/or Kerberos U2U, such as Samba AD members or systems using krb5 for NFS. The crash occurs during Network Level Authentication (NLA) connection teardown and requires a failed authentication attempt.
Recommendations Upgrade to FreeRDP version 3.24.2 or later.

Exploit

Fix

DoS

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-04674
CVE-2026-33995
GHSA-MV25-F4P2-5MXX
OPENSUSE-SU-2026:10633-1
OPENSUSE-SU-2026:20657-1
OPENSUSE-SU-2026:21116-1
SUSE-SU-2026:21436-1
SUSE-SU-2026:22194-1
SUSE-SU-2026:3562-1
USN-8561-1

Affected Products

Freerdp
Red Os
Samba
Winpr
Krb5