RHSA-2026:66281HighCVSS 8.8

Red Hat Security Advisory: freerdp security update

Published
September 10, 2026
Last Modified
September 17, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2026-55194 — FreeRDP: FreeRDP: Heap-buffer-overflow allows arbitrary code execution via crafted RPC response CVE-2026-67288 — FreeRDP: FreeRDP: Denial of Service via crafted smartcard cache requests CVE-2026-67291 — FreeRDP: FreeRDP: Denial of Service via heap out-of-bounds read CVE-2026-67301 — FreeRDP: FreeRDP: Memory disclosure or denial of service via crafted RDP update orders

🎯 Affected products34

  • Red Hat Enterprise Linux AppStream AUS (v.8.6)
  • Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6)
  • freerdp-2:2.2.0-7.el8_6.12.src as a component of Red Hat Enterprise Linux AppStream AUS (v.8.6)
  • freerdp-2:2.2.0-7.el8_6.12.src as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6)
  • freerdp-2:2.2.0-7.el8_6.12.x86_64 as a component of Red Hat Enterprise Linux AppStream AUS (v.8.6)
  • freerdp-2:2.2.0-7.el8_6.12.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6)
  • freerdp-debuginfo-2:2.2.0-7.el8_6.12.i686 as a component of Red Hat Enterprise Linux AppStream AUS (v.8.6)
  • freerdp-debuginfo-2:2.2.0-7.el8_6.12.i686 as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6)
  • freerdp-debuginfo-2:2.2.0-7.el8_6.12.x86_64 as a component of Red Hat Enterprise Linux AppStream AUS (v.8.6)
  • freerdp-debuginfo-2:2.2.0-7.el8_6.12.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6)
  • freerdp-debugsource-2:2.2.0-7.el8_6.12.i686 as a component of Red Hat Enterprise Linux AppStream AUS (v.8.6)
  • freerdp-debugsource-2:2.2.0-7.el8_6.12.i686 as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6)
  • freerdp-debugsource-2:2.2.0-7.el8_6.12.x86_64 as a component of Red Hat Enterprise Linux AppStream AUS (v.8.6)
  • freerdp-debugsource-2:2.2.0-7.el8_6.12.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6)
  • freerdp-libs-2:2.2.0-7.el8_6.12.i686 as a component of Red Hat Enterprise Linux AppStream AUS (v.8.6)
  • freerdp-libs-2:2.2.0-7.el8_6.12.i686 as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6)
  • freerdp-libs-2:2.2.0-7.el8_6.12.x86_64 as a component of Red Hat Enterprise Linux AppStream AUS (v.8.6)
  • freerdp-libs-2:2.2.0-7.el8_6.12.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6)
  • freerdp-libs-debuginfo-2:2.2.0-7.el8_6.12.i686 as a component of Red Hat Enterprise Linux AppStream AUS (v.8.6)
  • freerdp-libs-debuginfo-2:2.2.0-7.el8_6.12.i686 as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6)
  • freerdp-libs-debuginfo-2:2.2.0-7.el8_6.12.x86_64 as a component of Red Hat Enterprise Linux AppStream AUS (v.8.6)
  • freerdp-libs-debuginfo-2:2.2.0-7.el8_6.12.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6)
  • libwinpr-2:2.2.0-7.el8_6.12.i686 as a component of Red Hat Enterprise Linux AppStream AUS (v.8.6)
  • libwinpr-2:2.2.0-7.el8_6.12.i686 as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6)
  • libwinpr-2:2.2.0-7.el8_6.12.x86_64 as a component of Red Hat Enterprise Linux AppStream AUS (v.8.6)
  • libwinpr-2:2.2.0-7.el8_6.12.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6)
  • libwinpr-debuginfo-2:2.2.0-7.el8_6.12.i686 as a component of Red Hat Enterprise Linux AppStream AUS (v.8.6)
  • libwinpr-debuginfo-2:2.2.0-7.el8_6.12.i686 as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6)
  • libwinpr-debuginfo-2:2.2.0-7.el8_6.12.x86_64 as a component of Red Hat Enterprise Linux AppStream AUS (v.8.6)
  • libwinpr-debuginfo-2:2.2.0-7.el8_6.12.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6)
  • +4 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this vulnerability, avoid connecting through untrusted TS Gateways (RD Gateways) or disable gateway parameters (such as omitting `/g:` in `xfreerdp`) to force direct RDP connections and bypass RPC response parsing. Workaround: If smartcard redirection/emulation is unused, do not enable it (omit /smartcard and /smartcard-logon, or start with /smartcard:off). Only connect FreeRDP clients to trusted RDP endpoints Workaround: To mitigate this issue, avoid connecting FreeRDP clients to untrusted or potentially malicious RDP servers. If such connections are required, run the client on a dedicated, isolated system so a client crash is contained and does not impact other workloads. Workaround: To mitigate this issue, avoid enabling the `async-update` feature when using FreeRDP clients. This feature is not enabled by default. If `xfreerdp` is used, ensure the `/async-update` command-line option is not specified. Disabling this feature may impact performance in certain RDP sessions where asynchronous updates are beneficial.

🔗 References (7)