Red Hat Security Advisory: freerdp security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2026-91953 — FreeRDP: FreeRDP: Heap buffer overflow via oversized LB_LOAD_BALANCE_INFO routing token can lead to heap corruption. CVE-2026-91954 — FreeRDP: FreeRDP: Denial of Service via crafted Surface Bits command CVE-2026-91956 — FreeRDP: FreeRDP: Denial of Service via out-of-bounds read in URBDRC channel CVE-2026-91959 — FreeRDP: FreeRDP: Denial of Service due to buffer over-read in RPC gateway CVE-2026-91963 — FreeRDP: FreeRDP: Remote code execution via uninitialized heap memory disclosure CVE-2026-91964 — FreeRDP: FreeRDP: Remote code execution via heap buffer overflow in Server Redirection PDU
🎯 Affected products67
- Red Hat Enterprise Linux AppStream (v. 8)
- Red Hat Enterprise Linux CRB (v. 8)
- freerdp-2:2.11.7-14.el8_10.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- freerdp-2:2.11.7-14.el8_10.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
- freerdp-2:2.11.7-14.el8_10.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)
- freerdp-2:2.11.7-14.el8_10.src as a component of Red Hat Enterprise Linux AppStream (v. 8)
- freerdp-2:2.11.7-14.el8_10.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- freerdp-debuginfo-2:2.11.7-14.el8_10.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- freerdp-debuginfo-2:2.11.7-14.el8_10.aarch64 as a component of Red Hat Enterprise Linux CRB (v. 8)
- freerdp-debuginfo-2:2.11.7-14.el8_10.i686 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- freerdp-debuginfo-2:2.11.7-14.el8_10.i686 as a component of Red Hat Enterprise Linux CRB (v. 8)
- freerdp-debuginfo-2:2.11.7-14.el8_10.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
- freerdp-debuginfo-2:2.11.7-14.el8_10.ppc64le as a component of Red Hat Enterprise Linux CRB (v. 8)
- freerdp-debuginfo-2:2.11.7-14.el8_10.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)
- freerdp-debuginfo-2:2.11.7-14.el8_10.s390x as a component of Red Hat Enterprise Linux CRB (v. 8)
- freerdp-debuginfo-2:2.11.7-14.el8_10.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- freerdp-debuginfo-2:2.11.7-14.el8_10.x86_64 as a component of Red Hat Enterprise Linux CRB (v. 8)
- freerdp-debugsource-2:2.11.7-14.el8_10.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- freerdp-debugsource-2:2.11.7-14.el8_10.aarch64 as a component of Red Hat Enterprise Linux CRB (v. 8)
- freerdp-debugsource-2:2.11.7-14.el8_10.i686 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- freerdp-debugsource-2:2.11.7-14.el8_10.i686 as a component of Red Hat Enterprise Linux CRB (v. 8)
- freerdp-debugsource-2:2.11.7-14.el8_10.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
- freerdp-debugsource-2:2.11.7-14.el8_10.ppc64le as a component of Red Hat Enterprise Linux CRB (v. 8)
- freerdp-debugsource-2:2.11.7-14.el8_10.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)
- freerdp-debugsource-2:2.11.7-14.el8_10.s390x as a component of Red Hat Enterprise Linux CRB (v. 8)
- freerdp-debugsource-2:2.11.7-14.el8_10.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- freerdp-debugsource-2:2.11.7-14.el8_10.x86_64 as a component of Red Hat Enterprise Linux CRB (v. 8)
- freerdp-devel-2:2.11.7-14.el8_10.aarch64 as a component of Red Hat Enterprise Linux CRB (v. 8)
- freerdp-devel-2:2.11.7-14.el8_10.i686 as a component of Red Hat Enterprise Linux CRB (v. 8)
- freerdp-devel-2:2.11.7-14.el8_10.ppc64le as a component of Red Hat Enterprise Linux CRB (v. 8)
- +37 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To prevent exploitation of this heap buffer overflow, FreeRDP clients should only be used to connect to trusted RDP servers. This operational control reduces the risk of encountering a malicious server redirection PDU. Workaround: To mitigate this issue, users should avoid connecting to untrusted or unknown RDP servers with FreeRDP clients. This vulnerability requires a FreeRDP client to connect to a malicious RDP server to be exploited. Workaround: To mitigate this issue, users should avoid connecting to untrusted or unverified RDP servers. Restricting FreeRDP client connections to known, trusted RDP servers can prevent exploitation of this vulnerability. Workaround: To mitigate this issue, restrict network access to any FreeRDP instance operating in a server or gateway role, limiting connections to trusted clients or networks. If FreeRDP is used as a client, avoid connecting to untrusted or malicious RDP servers to prevent exploitation. Workaround: To reduce exposure, avoid connecting to untrusted RDP servers or disable the FreeRDP USB redirection channel if it is not required. When using the `xfreerdp` client, ensure that USB redirection is not enabled. This can be done by omitting the `/usb` or `/usb-redir` command-line options, or by explicitly disabling the `urbdrc` channel through FreeRDP configuration if available. Disabling this feature will prevent the redirection of USB devices to the remote session. Workaround: Users of FreeRDP clients should avoid connecting to untrusted or unknown RDP servers. This operational control reduces the risk of exploitation, as a malicious server is required to trigger the heap-based buffer overflow.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:76747
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533906
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533911
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533927
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533930
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533951
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533959
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_76747.json