Red Hat Security Advisory: freerdp security update
🔗 CVE IDs covered (11)
📋 Description
CVE-2026-85089 — FreeRDP: freerdp-proxy: FreeRDP: Information disclosure via uninitialized heap memory in Save Session Info PDU CVE-2026-91946 — FreeRDP: FreeRDP: Information Disclosure via RDPGFX ResetGraphics PDU CVE-2026-91947 — FreeRDP: FreeRDP: Use-after-free vulnerability in DRDYNVC parser leads to memory corruption CVE-2026-91950 — FreeRDP: FreeRDP: Out-of-bounds read leads to denial of service or information disclosure CVE-2026-91953 — FreeRDP: FreeRDP: Heap buffer overflow via oversized LB_LOAD_BALANCE_INFO routing token can lead to heap corruption. CVE-2026-91954 — FreeRDP: FreeRDP: Denial of Service via crafted Surface Bits command CVE-2026-91956 — FreeRDP: FreeRDP: Denial of Service via out-of-bounds read in URBDRC channel CVE-2026-91959 — FreeRDP: FreeRDP: Denial of Service due to buffer over-read in RPC gateway CVE-2026-91960 — FreeRDP: FreeRDP: Denial of Service via integer overflow and double free in WinPR CVE-2026-91963 — FreeRDP: FreeRDP: Remote code execution via uninitialized heap memory disclosure CVE-2026-91964 — FreeRDP: FreeRDP: Remote code execution via heap buffer overflow in Server Redirection PDU
🎯 Affected products67
- Red Hat Enterprise Linux AppStream (v. 10)
- Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- freerdp-2:3.10.3-12.el10_2.14.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- freerdp-2:3.10.3-12.el10_2.14.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
- freerdp-2:3.10.3-12.el10_2.14.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
- freerdp-2:3.10.3-12.el10_2.14.src as a component of Red Hat Enterprise Linux AppStream (v. 10)
- freerdp-2:3.10.3-12.el10_2.14.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- freerdp-debuginfo-2:3.10.3-12.el10_2.14.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- freerdp-debuginfo-2:3.10.3-12.el10_2.14.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- freerdp-debuginfo-2:3.10.3-12.el10_2.14.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
- freerdp-debuginfo-2:3.10.3-12.el10_2.14.ppc64le as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- freerdp-debuginfo-2:3.10.3-12.el10_2.14.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
- freerdp-debuginfo-2:3.10.3-12.el10_2.14.s390x as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- freerdp-debuginfo-2:3.10.3-12.el10_2.14.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- freerdp-debuginfo-2:3.10.3-12.el10_2.14.x86_64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- freerdp-debugsource-2:3.10.3-12.el10_2.14.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- freerdp-debugsource-2:3.10.3-12.el10_2.14.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- freerdp-debugsource-2:3.10.3-12.el10_2.14.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
- freerdp-debugsource-2:3.10.3-12.el10_2.14.ppc64le as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- freerdp-debugsource-2:3.10.3-12.el10_2.14.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
- freerdp-debugsource-2:3.10.3-12.el10_2.14.s390x as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- freerdp-debugsource-2:3.10.3-12.el10_2.14.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- freerdp-debugsource-2:3.10.3-12.el10_2.14.x86_64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- freerdp-devel-2:3.10.3-12.el10_2.14.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- freerdp-devel-2:3.10.3-12.el10_2.14.ppc64le as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- freerdp-devel-2:3.10.3-12.el10_2.14.s390x as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- freerdp-devel-2:3.10.3-12.el10_2.14.x86_64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- freerdp-libs-2:3.10.3-12.el10_2.14.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- freerdp-libs-2:3.10.3-12.el10_2.14.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
- freerdp-libs-2:3.10.3-12.el10_2.14.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
- +37 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, restrict network access to FreeRDP server instances to only trusted clients and networks. Configure firewall rules to limit inbound connections to the RDP port (typically 3389) from untrusted sources. If FreeRDP server functionality is not required, consider disabling or uninstalling the FreeRDP server component. Workaround: The vulnerability requires an authenticated client to interact with the FreeRDP server. To mitigate this issue, restrict network access to the FreeRDP server to only trusted clients and networks. If the FreeRDP server functionality is not required, consider disabling or uninstalling the FreeRDP server component to eliminate the attack surface. Workaround: To mitigate this issue, users should avoid connecting to untrusted or potentially malicious RDP servers. Restricting FreeRDP client connections to only known and trusted RDP servers significantly reduces the attack surface. If connecting to untrusted servers is unavoidable, consider using a highly isolated environment for the client. Workaround: To prevent exploitation of this heap buffer overflow, FreeRDP clients should only be used to connect to trusted RDP servers. This operational control reduces the risk of encountering a malicious server redirection PDU. Workaround: To mitigate this issue, users should avoid connecting to untrusted or unknown RDP servers with FreeRDP clients. This vulnerability requires a FreeRDP client to connect to a malicious RDP server to be exploited. Workaround: To mitigate this issue, users should avoid connecting to untrusted or unverified RDP servers. Restricting FreeRDP client connections to known, trusted RDP servers can prevent exploitation of this vulnerability. Workaround: To mitigate this issue, restrict network access to any FreeRDP instance operating in a server or gateway role, limiting connections to trusted clients or networks. If FreeRDP is used as a client, avoid connecting to untrusted or malicious RDP servers to prevent exploitation. Workaround: To mitigate this issue, FreeRDP clients should only connect to trusted and verified Remote Desktop Gateway servers. Connecting to untrusted or unverified servers may expose the client to denial of service attacks. Workaround: To reduce exposure, avoid connecting to untrusted RDP servers or disable the FreeRDP USB redirection channel if it is not required. When using the `xfreerdp` client, ensure that USB redirection is not enabled. This can be done by omitting the `/usb` or `/usb-redir` command-line options, or by explicitly disabling the `urbdrc` channel through FreeRDP configuration if available. Disabling this feature will prevent the redirection of USB devices to the remote session. Workaround: Users of FreeRDP clients should avoid connecting to untrusted or unknown RDP servers. This operational control reduces the risk of exploitation, as a malicious server is required to trigger the heap-based buffer overflow.
🔗 References (14)
- selfhttps://access.redhat.com/errata/RHSA-2026:75570
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2527811
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533906
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533911
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533913
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533927
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533930
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533942
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533951
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533954
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533957
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533959
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_75570.json