Red Hat Security Advisory: freerdp security update
🔗 CVE IDs covered (23)
📋 Description
CVE-2026-22852 — freerdp: FreeRDP heap-buffer-overflow CVE-2026-22853 — freerdp: FreeRDP heap-buffer-overflow CVE-2026-22854 — freerdp: FreeRDP heap-buffer-overflow CVE-2026-22855 — freerdp: FreeRDP heap-buffer-overflow CVE-2026-22856 — freerdp: FreeRDP heap-use-after-free CVE-2026-22858 — freerdp: FreeRDP global-buffer-overflow CVE-2026-22859 — freerdp: FreeRDP heap-buffer-overflow CVE-2026-23732 — freerdp: FreeRDP: Denial of Service via FastGlyph parsing buffer overflow CVE-2026-23948 — freerdp: FreeRDP has a NULL Pointer Dereference in rdp_write_logon_info_v2() CVE-2026-24491 — freerdp: FreeRDP has a heap-use-after-free in video_timer CVE-2026-24675 — freerdp: FreeRDP has a Heap-use-after-free in urb_select_interface CVE-2026-24676 — freerdp: FreeRDP: Denial of Service via use-after-free in AUDIN format renegotiation CVE-2026-24678 — freerdp: FreeRDP: Denial of Service via use after free in ecam_channel_write CVE-2026-24679 — freerdp: FreeRDP has a heap-buffer-overflow in urb_select_interface CVE-2026-24681 — freerdp: FreeRDP has a heap-use-after-free in urb_bulk_transfer_cb CVE-2026-24682 — freerdp: FreeRDP has a Heap-buffer-overflow in audio_formats_free CVE-2026-24683 — freerdp: FreeRDP has a heap-use-after-free in ainput_send_input_event CVE-2026-24684 — freerdp: FreeRDP has a Heap-use-after-free in play_thread CVE-2026-26955 — freerdp: FreeRDP: Arbitrary code execution via heap buffer overflow in GDI surface pipeline CVE-2026-26965 — freerdp: FreeRDP: Arbitrary code execution via heap out-of-bounds write in RLE planar decode path CVE-2026-31806 — freerdp: FreeRDP: Arbitrary code execution via crafted Remote Desktop Protocol (RDP) server messages CVE-2026-33983 — FreeRDP: FreeRDP: Denial of Service via specially crafted Remote Desktop Protocol messages CVE-2026-33984 — FreeRDP: FreeRDP: Heap buffer overflow allows arbitrary code execution via crafted pixel data
🔗 References (26)
- selfhttps://access.redhat.com/errata/RHSA-2026:19033
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2429645
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2429647
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2429649
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2429650
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2429652
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2429653
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2429654
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2430881
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2438197
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2438201
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2438202
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2438207
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2438208
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2438210
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2438212
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2438216
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2438217
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2438221
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2442959
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2443132
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2447376
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2453219
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2453220
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_19033.json