RHSA-2026:68706HighCVSS 8.8

Red Hat Security Advisory: freerdp security update

Published
September 17, 2026
Last Modified
September 25, 2026

🔗 CVE IDs covered (14)

📋 Description

CVE-2026-55194 — FreeRDP: FreeRDP: Heap-buffer-overflow allows arbitrary code execution via crafted RPC response CVE-2026-63633 — freerdp: FreeRDP: Arbitrary code execution via heap buffer overflow in Opus audio decode CVE-2026-63652 — FreeRDP: FreeRDP: Denial of Service and heap corruption via malformed RDP audio PDU CVE-2026-67288 — FreeRDP: FreeRDP: Denial of Service via crafted smartcard cache requests CVE-2026-67290 — FreeRDP: FreeRDP: Denial of Service via malformed media data CVE-2026-67291 — FreeRDP: FreeRDP: Denial of Service via heap out-of-bounds read CVE-2026-67296 — FreeRDP: FreeRDP: Denial of Service due to RDPEI message processing CVE-2026-67297 — FreeRDP: FreeRDP: Resource exhaustion due to oversized chunked HTTP responses CVE-2026-67298 — FreeRDP: FreeRDP: Denial of Service via integer underflow in RAIL channel handling CVE-2026-67301 — FreeRDP: FreeRDP: Memory disclosure or denial of service via crafted RDP update orders CVE-2026-67304 — FreeRDP: FreeRDP: Denial of Service via null pointer dereference in smartcard cleanup CVE-2026-69159 — FreeRDP: FreeRDP: Out-of-bounds read leads to denial of service and information disclosure CVE-2026-73241 — FreeRDP: FreeRDP: Authentication bypass via incorrect RDSTLS PDU handling CVE-2026-73242 — FreeRDP: FreeRDP: Out-of-bounds memory access in Kerberos decryption

🎯 Affected products67

  • Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0)
  • freerdp-2:3.10.3-3.el10_0.16.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • freerdp-2:3.10.3-3.el10_0.16.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • freerdp-2:3.10.3-3.el10_0.16.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • freerdp-2:3.10.3-3.el10_0.16.src as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • freerdp-2:3.10.3-3.el10_0.16.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • freerdp-debuginfo-2:3.10.3-3.el10_0.16.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • freerdp-debuginfo-2:3.10.3-3.el10_0.16.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0)
  • freerdp-debuginfo-2:3.10.3-3.el10_0.16.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • freerdp-debuginfo-2:3.10.3-3.el10_0.16.ppc64le as a component of Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0)
  • freerdp-debuginfo-2:3.10.3-3.el10_0.16.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • freerdp-debuginfo-2:3.10.3-3.el10_0.16.s390x as a component of Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0)
  • freerdp-debuginfo-2:3.10.3-3.el10_0.16.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • freerdp-debuginfo-2:3.10.3-3.el10_0.16.x86_64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0)
  • freerdp-debugsource-2:3.10.3-3.el10_0.16.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • freerdp-debugsource-2:3.10.3-3.el10_0.16.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0)
  • freerdp-debugsource-2:3.10.3-3.el10_0.16.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • freerdp-debugsource-2:3.10.3-3.el10_0.16.ppc64le as a component of Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0)
  • freerdp-debugsource-2:3.10.3-3.el10_0.16.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • freerdp-debugsource-2:3.10.3-3.el10_0.16.s390x as a component of Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0)
  • freerdp-debugsource-2:3.10.3-3.el10_0.16.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • freerdp-debugsource-2:3.10.3-3.el10_0.16.x86_64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0)
  • freerdp-devel-2:3.10.3-3.el10_0.16.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0)
  • freerdp-devel-2:3.10.3-3.el10_0.16.ppc64le as a component of Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0)
  • freerdp-devel-2:3.10.3-3.el10_0.16.s390x as a component of Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0)
  • freerdp-devel-2:3.10.3-3.el10_0.16.x86_64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0)
  • freerdp-libs-2:3.10.3-3.el10_0.16.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • freerdp-libs-2:3.10.3-3.el10_0.16.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • freerdp-libs-2:3.10.3-3.el10_0.16.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • +37 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this vulnerability, avoid connecting through untrusted TS Gateways (RD Gateways) or disable gateway parameters (such as omitting `/g:` in `xfreerdp`) to force direct RDP connections and bypass RPC response parsing. Workaround: To mitigate this vulnerability, disable audio redirection on client connections by omitting audio parameters (such as `/sound` or `/audio`) in `xfreerdp` to bypass client-side DSP audio decoding. Workaround: To mitigate this issue, disable audio redirection on the FreeRDP server configuration if remote audio capability is not required. Workaround: If smartcard redirection/emulation is unused, do not enable it (omit /smartcard and /smartcard-logon, or start with /smartcard:off). Only connect FreeRDP clients to trusted RDP endpoints Workaround: To mitigate this issue, disable the Terminal Services Multimedia Redirection (TSMF) feature when connecting to untrusted RDP servers. This prevents the vulnerable media processing from being engaged. For `xfreerdp` clients, use the `/disable-tsmf` or `/tsmf:off` command-line option: `xfreerdp /disable-tsmf <server_address>` Disabling TSMF will prevent multimedia content from being redirected during the RDP session. Workaround: To mitigate this issue, avoid connecting FreeRDP clients to untrusted or potentially malicious RDP servers. If such connections are required, run the client on a dedicated, isolated system so a client crash is contained and does not impact other workloads. Workaround: To mitigate this do not expose FreeRDP server/proxy/shadow (freerdp-shadow-cli / freerdp-proxy) to untrusted networks—allow only trusted clients via firewall, or disable those services if unused. Workaround: To mitigate this issue, FreeRDP clients should only connect to trusted Remote Desktop Gateway endpoints. Avoiding connections to untrusted or potentially compromised gateways will prevent exposure to malicious servers that could exploit this vulnerability by sending oversized chunked HTTP responses. Workaround: To mitigate this issue do not expose FreeRDP server/proxy/shadow (freerdp-shadow-cli / freerdp-proxy) to untrusted networks—allow only trusted clients via firewall, or disable those services if unused. Workaround: To mitigate this issue, avoid enabling the `async-update` feature when using FreeRDP clients. This feature is not enabled by default. If `xfreerdp` is used, ensure the `/async-update` command-line option is not specified. Disabling this feature may impact performance in certain RDP sessions where asynchronous updates are beneficial. Workaround: To mitigate this issue, disable smartcard redirection in FreeRDP client configurations if smartcard functionality is not required. This can typically be achieved by launching the `xfreerdp` client without the `/smartcard` option, or by explicitly setting `/smartcard:no` if a configuration file is used. Disabling smartcard redirection will prevent the use of smartcard devices with FreeRDP sessions. Workaround: To mitigate this vulnerability, disable RDP planar graphics codec acceleration in client settings or force alternative graphics rendering modes (such as standard RemoteFX or H.264) when connecting to untrusted RDP servers. Workaround: Do not enable RDSTLS server authentication (RdstlsSecurity); it is disabled by default. If FreeRDP is deployed as an RDP server with RDSTLS enabled, disable RdstlsSecurity Workaround: Use FreeRDP with Kerberos/NLA only against trusted RDP peers. As a client, avoid connecting to untrusted RDP servers; as a server, restrict inbound RDP to trusted clients using host firewall rules or network segmentation.

🔗 References (18)