RHSA-2026:76747HighCVSS 8.8

Red Hat Security Advisory: freerdp security update

Published
October 6, 2026
Last Modified
October 6, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2026-91953 — FreeRDP: FreeRDP: Heap buffer overflow via oversized LB_LOAD_BALANCE_INFO routing token can lead to heap corruption. CVE-2026-91954 — FreeRDP: FreeRDP: Denial of Service via crafted Surface Bits command CVE-2026-91956 — FreeRDP: FreeRDP: Denial of Service via out-of-bounds read in URBDRC channel CVE-2026-91959 — FreeRDP: FreeRDP: Denial of Service due to buffer over-read in RPC gateway CVE-2026-91963 — FreeRDP: FreeRDP: Remote code execution via uninitialized heap memory disclosure CVE-2026-91964 — FreeRDP: FreeRDP: Remote code execution via heap buffer overflow in Server Redirection PDU

🎯 Affected products67

  • Red Hat Enterprise Linux AppStream (v. 8)
  • Red Hat Enterprise Linux CRB (v. 8)
  • freerdp-2:2.11.7-14.el8_10.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • freerdp-2:2.11.7-14.el8_10.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • freerdp-2:2.11.7-14.el8_10.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • freerdp-2:2.11.7-14.el8_10.src as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • freerdp-2:2.11.7-14.el8_10.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • freerdp-debuginfo-2:2.11.7-14.el8_10.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • freerdp-debuginfo-2:2.11.7-14.el8_10.aarch64 as a component of Red Hat Enterprise Linux CRB (v. 8)
  • freerdp-debuginfo-2:2.11.7-14.el8_10.i686 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • freerdp-debuginfo-2:2.11.7-14.el8_10.i686 as a component of Red Hat Enterprise Linux CRB (v. 8)
  • freerdp-debuginfo-2:2.11.7-14.el8_10.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • freerdp-debuginfo-2:2.11.7-14.el8_10.ppc64le as a component of Red Hat Enterprise Linux CRB (v. 8)
  • freerdp-debuginfo-2:2.11.7-14.el8_10.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • freerdp-debuginfo-2:2.11.7-14.el8_10.s390x as a component of Red Hat Enterprise Linux CRB (v. 8)
  • freerdp-debuginfo-2:2.11.7-14.el8_10.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • freerdp-debuginfo-2:2.11.7-14.el8_10.x86_64 as a component of Red Hat Enterprise Linux CRB (v. 8)
  • freerdp-debugsource-2:2.11.7-14.el8_10.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • freerdp-debugsource-2:2.11.7-14.el8_10.aarch64 as a component of Red Hat Enterprise Linux CRB (v. 8)
  • freerdp-debugsource-2:2.11.7-14.el8_10.i686 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • freerdp-debugsource-2:2.11.7-14.el8_10.i686 as a component of Red Hat Enterprise Linux CRB (v. 8)
  • freerdp-debugsource-2:2.11.7-14.el8_10.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • freerdp-debugsource-2:2.11.7-14.el8_10.ppc64le as a component of Red Hat Enterprise Linux CRB (v. 8)
  • freerdp-debugsource-2:2.11.7-14.el8_10.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • freerdp-debugsource-2:2.11.7-14.el8_10.s390x as a component of Red Hat Enterprise Linux CRB (v. 8)
  • freerdp-debugsource-2:2.11.7-14.el8_10.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • freerdp-debugsource-2:2.11.7-14.el8_10.x86_64 as a component of Red Hat Enterprise Linux CRB (v. 8)
  • freerdp-devel-2:2.11.7-14.el8_10.aarch64 as a component of Red Hat Enterprise Linux CRB (v. 8)
  • freerdp-devel-2:2.11.7-14.el8_10.i686 as a component of Red Hat Enterprise Linux CRB (v. 8)
  • freerdp-devel-2:2.11.7-14.el8_10.ppc64le as a component of Red Hat Enterprise Linux CRB (v. 8)
  • +37 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To prevent exploitation of this heap buffer overflow, FreeRDP clients should only be used to connect to trusted RDP servers. This operational control reduces the risk of encountering a malicious server redirection PDU. Workaround: To mitigate this issue, users should avoid connecting to untrusted or unknown RDP servers with FreeRDP clients. This vulnerability requires a FreeRDP client to connect to a malicious RDP server to be exploited. Workaround: To mitigate this issue, users should avoid connecting to untrusted or unverified RDP servers. Restricting FreeRDP client connections to known, trusted RDP servers can prevent exploitation of this vulnerability. Workaround: To mitigate this issue, restrict network access to any FreeRDP instance operating in a server or gateway role, limiting connections to trusted clients or networks. If FreeRDP is used as a client, avoid connecting to untrusted or malicious RDP servers to prevent exploitation. Workaround: To reduce exposure, avoid connecting to untrusted RDP servers or disable the FreeRDP USB redirection channel if it is not required. When using the `xfreerdp` client, ensure that USB redirection is not enabled. This can be done by omitting the `/usb` or `/usb-redir` command-line options, or by explicitly disabling the `urbdrc` channel through FreeRDP configuration if available. Disabling this feature will prevent the redirection of USB devices to the remote session. Workaround: Users of FreeRDP clients should avoid connecting to untrusted or unknown RDP servers. This operational control reduces the risk of exploitation, as a malicious server is required to trigger the heap-based buffer overflow.

🔗 References (9)