freerdp-2.11.7-11.el8_10
エラータID: AXSA:2026-1534:25
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.
Security Fix(es):
* FreeRDP: FreeRDP: Arbitrary code execution via malicious RDP files (CVE-2026-64624)
* FreeRDP: FreeRDP: Denial of Service via crafted WindowIcon async message (CVE-2026-67299)
* FreeRDP: FreeRDP: HTTP Proxy Request Injection via Redirection (CVE-2026-67289)
* FreeRDP: FreeRDP: Remote code execution or denial of service via audio input integer overflow (CVE-2026-68580)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-64624
FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP files with /rdp2tcp, /cert:ignore, or /drive options to execute arbitrary commands, bypass certificate validation, or expose local filesystems without user interaction.
CVE-2026-67289
FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.
CVE-2026-67299
FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled (e.g. xfreerdp /async-update). In update_message_WindowIcon() a shallow CopyMemory() overwrites a freshly allocated lParam->iconInfo with the parser-owned windowIcon->iconInfo pointer. After the parser callback returns, update_recv_window_info_order() frees window_icon.iconInfo, but the queued async message still retains and later dispatches that stale pointer. A malicious or compromised RDP server sending a crafted RAIL Window Alternate Secondary Order with WINDOW_ORDER_ICON can trigger use-after-free, leading to memory corruption and client crash.
CVE-2026-68580
FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can supply a malicious FramesPerPacket value causing allocation size wraparound, resulting in heap-based buffer overflow on ALSA or denial of service on all platforms.
Update packages.
FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP files with /rdp2tcp, /cert:ignore, or /drive options to execute arbitrary commands, bypass certificate validation, or expose local filesystems without user interaction.
FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.
FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled (e.g. xfreerdp /async-update). In update_message_WindowIcon() a shallow CopyMemory() overwrites a freshly allocated lParam->iconInfo with the parser-owned windowIcon->iconInfo pointer. After the parser callback returns, update_recv_window_info_order() frees window_icon.iconInfo, but the queued async message still retains and later dispatches that stale pointer. A malicious or compromised RDP server sending a crafted RAIL Window Alternate Secondary Order with WINDOW_ORDER_ICON can trigger use-after-free, leading to memory corruption and client crash.
FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can supply a malicious FramesPerPacket value causing allocation size wraparound, resulting in heap-based buffer overflow on ALSA or denial of service on all platforms.
N/A
SRPMS
- freerdp-2.11.7-11.el8_10.src.rpm
MD5: b8abf9b85aa46662f6e27f049ac45716
SHA-256: 3ba1288a627fb3888afe5bcb7d791bf4c06e16f43aa155230f6ddd84c90aaad1
Size: 7.05 MB
Asianux Server 8 for x86_64
- freerdp-2.11.7-11.el8_10.x86_64.rpm
MD5: d35f622082b82baffb7aa66759c5a460
SHA-256: ead2efab7d9c03f535ebec831c05272c839cfbc50698af8f2b1bcee6338e29eb
Size: 120.34 kB - freerdp-devel-2.11.7-11.el8_10.i686.rpm
MD5: 26c759de8e160881b5e6ba38b85fd45e
SHA-256: ca2b713014df0647fe2a8b5e3052015965b16eceaf89ebfee32fe861cbbad756
Size: 148.54 kB - freerdp-devel-2.11.7-11.el8_10.x86_64.rpm
MD5: 0b09a54a0989d069495ad336a61a4271
SHA-256: a09858121bf4536647905331eae7d46409b93c66564b419e9f73654c726ce971
Size: 148.56 kB - freerdp-libs-2.11.7-11.el8_10.i686.rpm
MD5: a7107f22336cb478d1c0c8aeaa5ae4a5
SHA-256: 464ee9df48abac58507c93b6812a61da13cad307f69b010142972305e9bea021
Size: 878.72 kB - freerdp-libs-2.11.7-11.el8_10.x86_64.rpm
MD5: 701ef0ada3067511d272d76ac8ee8376
SHA-256: 8dbf72948122390c726802676c44a92ebe8c7545bf120b2d85f705a9303d2b13
Size: 931.03 kB - libwinpr-2.11.7-11.el8_10.i686.rpm
MD5: f29f3751a7d1dc4114c72bb1ffefefb8
SHA-256: dd41251c273f32f0a68203f29ccdcac56f2c9f026104600acaad682a92e56b76
Size: 364.41 kB - libwinpr-2.11.7-11.el8_10.x86_64.rpm
MD5: 86e23daa69f1f9d6eb90dfa3fa7de732
SHA-256: 7f99ab3fbb8e82647c5d45f7415ab496b587eb561c90097ab42c01933351da3f
Size: 380.49 kB - libwinpr-devel-2.11.7-11.el8_10.i686.rpm
MD5: f7b36082b0178ce2be0441e42d8a0930
SHA-256: 62924a4d61fc57c0983c167ed1f09e2d922575c16e1fa8eb2ce9985f6951bbb0
Size: 176.71 kB - libwinpr-devel-2.11.7-11.el8_10.x86_64.rpm
MD5: 99a1f0a902d325d4c934fd3369b4c2d2
SHA-256: 1e091082da8a8429ba99e1ae2504b7838f4db10fd87298e5a954dedbbbb37fd4
Size: 176.69 kB