freerdp-2.11.7-7.el9_8.6

エラータID: AXSA:2026-1752:27

Release date: 
Thursday, September 3, 2026 - 22:49
Subject: 
freerdp-2.11.7-7.el9_8.6
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.

Security Fix(es):

* FreeRDP: FreeRDP: Memory disclosure or denial of service via crafted RDP update orders (CVE-2026-67301)
* FreeRDP: FreeRDP: Denial of Service via crafted smartcard cache requests (CVE-2026-67288)
* FreeRDP: FreeRDP: Denial of Service via heap out-of-bounds read (CVE-2026-67291)
* FreeRDP: FreeRDP: Heap-buffer-overflow allows arbitrary code execution via crafted RPC response (CVE-2026-55194)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-55194
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the server-declared alloc_hint rather than the actual StubLength about to be written. A malicious TS Gateway can send a PTYPE_RESPONSE with a small alloc_hint and a much larger frag_length, causing Stream_Write to copy attacker-controlled stub data beyond the 4096-byte pdu->s buffer. This can crash the client and may permit code execution through heap corruption. This issue is fixed in version 3.27.0.
CVE-2026-67288
FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emulation is enabled, attackers can send crafted smartcard cache requests with NULL lookup-name pointers to trigger strlen() on a null pointer, causing client process termination.
CVE-2026-67291
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-byte server-controlled declared fragment size but does not verify it fits within the remaining received buffer before allocating and copying that many bytes. A malicious RDP server can send a short fragment with an oversized declared size, causing the client to read beyond the allocated buffer, resulting in an out-of-bounds read and client crash.
CVE-2026-67301
FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders. When AsyncUpdate is enabled (e.g., xfreerdp /async-update), update_message_PolygonSC() and update_message_PolygonCB() allocate a fresh points array but copy point data from the address of the order structure instead of from polygonSC->points / polygonCB->points, resulting in a client-side out-of-bounds read. A malicious or compromised RDP server sending crafted PolygonSC/PolygonCB update orders can trigger memory disclosure or a client crash.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. freerdp-2.11.7-7.el9_8.6.src.rpm
    MD5: 3e4cd127cd3d596b5d781580ea900df0
    SHA-256: 882165223f23c71e5a6555169f97af0d88959ab69eebef8cc0ef5b3d6eea7420
    Size: 7.06 MB

Asianux Server 9 for x86_64
  1. freerdp-2.11.7-7.el9_8.6.x86_64.rpm
    MD5: c65d5790c2eb5cac18748fa4c67870e2
    SHA-256: c24fe55edc033016edb46af34335b38d4498d192864dde3e26ff78b0db106ef3
    Size: 113.14 kB
  2. freerdp-devel-2.11.7-7.el9_8.6.i686.rpm
    MD5: 438ec9253e2345d3f10cecb28658dcb5
    SHA-256: 8252998b299a32f46e8468118806f005c2c5ebed5509c8e2321ee35b10b21737
    Size: 177.20 kB
  3. freerdp-devel-2.11.7-7.el9_8.6.x86_64.rpm
    MD5: dc4e762e3268b3198903995b97f19b58
    SHA-256: d6ca35ba9a301ba79d4049adfca33104c4ef7b7d0c7a42824e083c3dd9b0c9aa
    Size: 177.21 kB
  4. freerdp-libs-2.11.7-7.el9_8.6.i686.rpm
    MD5: be3e7a6ccd1f460faf66475ba8ce3ce9
    SHA-256: 6f88971fff276afc7eb17797a37088b883f38c040821bf517b93072a384692d6
    Size: 852.72 kB
  5. freerdp-libs-2.11.7-7.el9_8.6.x86_64.rpm
    MD5: 3daf121b851235351cdb504040fd8f4d
    SHA-256: fc3e67f1d40149a020490da23aee855473c33f714381a397bd9a49b8ce084cef
    Size: 909.21 kB
  6. libwinpr-2.11.7-7.el9_8.6.i686.rpm
    MD5: 7dc7a84abe60d48982a45d4374432f8e
    SHA-256: fa566a25bc224f52925c601f9342e7c599a888a8eda0211061afc7e4c3a0176c
    Size: 341.28 kB
  7. libwinpr-2.11.7-7.el9_8.6.x86_64.rpm
    MD5: e5bc494dc417c3f53e6c58f4298ed247
    SHA-256: ea198b06d431e802bf0909c894e44b8da07852685002255768fd2206bec02368
    Size: 355.58 kB
  8. libwinpr-devel-2.11.7-7.el9_8.6.i686.rpm
    MD5: 6cab7dea8207668851c1268bd9808e02
    SHA-256: bbcf099d0e576b9504f314c234912f5e4c7d343beb04b6bfd7c3bd3bd6afcfda
    Size: 183.09 kB
  9. libwinpr-devel-2.11.7-7.el9_8.6.x86_64.rpm
    MD5: 35143b5d9d3e2204f88252f44feab2a0
    SHA-256: 69b331e595414e7602c8919fcfe9d57e66aa2e7058c60e7acda91544dbd10ca8
    Size: 183.09 kB