Red Hat Security Advisory: freerdp security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2026-64624 — FreeRDP: FreeRDP: Arbitrary code execution via malicious RDP files CVE-2026-67289 — FreeRDP: FreeRDP: HTTP Proxy Request Injection via Redirection CVE-2026-67299 — FreeRDP: FreeRDP: Denial of Service via crafted WindowIcon async message CVE-2026-68580 — FreeRDP: FreeRDP: Remote code execution or denial of service via audio input integer overflow
🎯 Affected products36
- Red Hat Enterprise Linux AppStream E4S (v.9.4)
- freerdp-2:2.11.2-1.el9_4.10.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- freerdp-2:2.11.2-1.el9_4.10.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- freerdp-2:2.11.2-1.el9_4.10.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- freerdp-2:2.11.2-1.el9_4.10.src as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- freerdp-2:2.11.2-1.el9_4.10.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- freerdp-debuginfo-2:2.11.2-1.el9_4.10.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- freerdp-debuginfo-2:2.11.2-1.el9_4.10.i686 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- freerdp-debuginfo-2:2.11.2-1.el9_4.10.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- freerdp-debuginfo-2:2.11.2-1.el9_4.10.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- freerdp-debuginfo-2:2.11.2-1.el9_4.10.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- freerdp-debugsource-2:2.11.2-1.el9_4.10.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- freerdp-debugsource-2:2.11.2-1.el9_4.10.i686 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- freerdp-debugsource-2:2.11.2-1.el9_4.10.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- freerdp-debugsource-2:2.11.2-1.el9_4.10.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- freerdp-debugsource-2:2.11.2-1.el9_4.10.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- freerdp-libs-2:2.11.2-1.el9_4.10.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- freerdp-libs-2:2.11.2-1.el9_4.10.i686 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- freerdp-libs-2:2.11.2-1.el9_4.10.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- freerdp-libs-2:2.11.2-1.el9_4.10.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- freerdp-libs-2:2.11.2-1.el9_4.10.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- freerdp-libs-debuginfo-2:2.11.2-1.el9_4.10.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- freerdp-libs-debuginfo-2:2.11.2-1.el9_4.10.i686 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- freerdp-libs-debuginfo-2:2.11.2-1.el9_4.10.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- freerdp-libs-debuginfo-2:2.11.2-1.el9_4.10.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- freerdp-libs-debuginfo-2:2.11.2-1.el9_4.10.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- libwinpr-2:2.11.2-1.el9_4.10.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- libwinpr-2:2.11.2-1.el9_4.10.i686 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- libwinpr-2:2.11.2-1.el9_4.10.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- libwinpr-2:2.11.2-1.el9_4.10.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- +6 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, users should avoid opening RDP files from untrusted or unknown sources. Ensure SELinux remains in enforcing mode. This is the most important existing Red Hat safeguard for this CVE, confining what an exploited FreeRDP process can access. Workaround: To mitigate this issue, FreeRDP clients should avoid connecting to untrusted RDP servers when configured to use an HTTP proxy. Alternatively, if connecting to potentially untrusted RDP servers, disable the HTTP proxy configuration for FreeRDP. Workaround: To mitigate this issue, avoid connecting to untrusted RDP servers. Additionally, refrain from using the `/async-update` command-line option when launching FreeRDP clients, as this feature is required to trigger the vulnerability. Workaround: To mitigate this issue, disable the audio input redirection channel when using FreeRDP clients. This can be achieved by using the `/audin:no` command-line option when launching `xfreerdp` or other FreeRDP-based clients. Disabling audio input redirection may impact functionality that relies on microphone input during the RDP session. Ensure to restart any active FreeRDP sessions for the change to take effect.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:58710
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2503096
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2509985
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2510004
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2510125
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_58710.json