freerdp-2.11.7-7.el9_8.5
エラータID: AXSA:2026-1629:26
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.
Security Fix(es):
* FreeRDP: FreeRDP: Arbitrary code execution via malicious RDP files (CVE-2026-64624)
* FreeRDP: FreeRDP: Denial of Service via crafted WindowIcon async message (CVE-2026-67299)
* FreeRDP: FreeRDP: HTTP Proxy Request Injection via Redirection (CVE-2026-67289)
* FreeRDP: FreeRDP: Remote code execution or denial of service via audio input integer overflow (CVE-2026-68580)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-64624
FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP files with /rdp2tcp, /cert:ignore, or /drive options to execute arbitrary commands, bypass certificate validation, or expose local filesystems without user interaction.
CVE-2026-67289
FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.
CVE-2026-67299
FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled (e.g. xfreerdp /async-update). In update_message_WindowIcon() a shallow CopyMemory() overwrites a freshly allocated lParam->iconInfo with the parser-owned windowIcon->iconInfo pointer. After the parser callback returns, update_recv_window_info_order() frees window_icon.iconInfo, but the queued async message still retains and later dispatches that stale pointer. A malicious or compromised RDP server sending a crafted RAIL Window Alternate Secondary Order with WINDOW_ORDER_ICON can trigger use-after-free, leading to memory corruption and client crash.
CVE-2026-68580
FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can supply a malicious FramesPerPacket value causing allocation size wraparound, resulting in heap-based buffer overflow on ALSA or denial of service on all platforms.
Update packages.
FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP files with /rdp2tcp, /cert:ignore, or /drive options to execute arbitrary commands, bypass certificate validation, or expose local filesystems without user interaction.
FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.
FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled (e.g. xfreerdp /async-update). In update_message_WindowIcon() a shallow CopyMemory() overwrites a freshly allocated lParam->iconInfo with the parser-owned windowIcon->iconInfo pointer. After the parser callback returns, update_recv_window_info_order() frees window_icon.iconInfo, but the queued async message still retains and later dispatches that stale pointer. A malicious or compromised RDP server sending a crafted RAIL Window Alternate Secondary Order with WINDOW_ORDER_ICON can trigger use-after-free, leading to memory corruption and client crash.
FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can supply a malicious FramesPerPacket value causing allocation size wraparound, resulting in heap-based buffer overflow on ALSA or denial of service on all platforms.
N/A
SRPMS
- freerdp-2.11.7-7.el9_8.5.src.rpm
MD5: 4bef1b83c774636f5f785e77946a0e69
SHA-256: 4dc9ce3aaa5c2a801624b719774803cff9baa8cc2f3fd3c4388e3af545eac317
Size: 7.06 MB
Asianux Server 9 for x86_64
- freerdp-2.11.7-7.el9_8.5.x86_64.rpm
MD5: 97fb55cb84e578954d8f3818098541ba
SHA-256: b088487c87ea500b83eb57bb5763ccfd2645f028b1f010cbb4ee45320ed0a161
Size: 112.90 kB - freerdp-devel-2.11.7-7.el9_8.5.i686.rpm
MD5: 5d6df98115e737ef8148deae88feefbd
SHA-256: 27141a6afc37b181c45762d458a4c9e47c78d04950e7420c786019085ddfcf1f
Size: 176.93 kB - freerdp-devel-2.11.7-7.el9_8.5.x86_64.rpm
MD5: 5eb477554f30de345fde9eca5cf47ab1
SHA-256: 094101dc2b0808d137694cc66f059fd38357660f9bbabb1b974c5bc61b67b0a3
Size: 177.06 kB - freerdp-libs-2.11.7-7.el9_8.5.i686.rpm
MD5: 624358de99769c0b14b7a21eba7da2c3
SHA-256: 90d1ce7714ae69f5c3e90923fa26c8a1e106d2500e4b0fda029cd7d8598ae124
Size: 852.56 kB - freerdp-libs-2.11.7-7.el9_8.5.x86_64.rpm
MD5: 8f8c8a7e1eaca6235812cf0e993cc9c2
SHA-256: d3a24749b7105839af68862bdf3e5887e28d04221d8c7399caa57088a8834822
Size: 909.07 kB - libwinpr-2.11.7-7.el9_8.5.i686.rpm
MD5: 783b73ccc1c8226e57682a59db519013
SHA-256: 861df9f61b82a42ae8b9df9fad91ee1c0b9a99c662192dd86e1dbcd8d1ecb90d
Size: 341.33 kB - libwinpr-2.11.7-7.el9_8.5.x86_64.rpm
MD5: d0b76c003b41ff71a909f16d74202ffa
SHA-256: 6b54e1a118cdb333b991a3dac6e366304f814c16973444b5e5d63113846e3198
Size: 356.38 kB - libwinpr-devel-2.11.7-7.el9_8.5.i686.rpm
MD5: e2e1f2c6fb0c91fb8df62301680a7d4c
SHA-256: 75380b8272c4dabaa3a5b2d78cba7bed0bc9b18f15860d2d5fae4ab070dec673
Size: 182.89 kB - libwinpr-devel-2.11.7-7.el9_8.5.x86_64.rpm
MD5: a46a76edf2bb6497d90908b70f49329f
SHA-256: 1bc60ad2363c3dc1518282e10b9a37afee5899142590add898fb18826dec6533
Size: 182.88 kB