freerdp-2.11.7-7.el9_8.6
エラータID: AXSA:2026-1752:27
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.
Security Fix(es):
* FreeRDP: FreeRDP: Memory disclosure or denial of service via crafted RDP update orders (CVE-2026-67301)
* FreeRDP: FreeRDP: Denial of Service via crafted smartcard cache requests (CVE-2026-67288)
* FreeRDP: FreeRDP: Denial of Service via heap out-of-bounds read (CVE-2026-67291)
* FreeRDP: FreeRDP: Heap-buffer-overflow allows arbitrary code execution via crafted RPC response (CVE-2026-55194)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-55194
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the server-declared alloc_hint rather than the actual StubLength about to be written. A malicious TS Gateway can send a PTYPE_RESPONSE with a small alloc_hint and a much larger frag_length, causing Stream_Write to copy attacker-controlled stub data beyond the 4096-byte pdu->s buffer. This can crash the client and may permit code execution through heap corruption. This issue is fixed in version 3.27.0.
CVE-2026-67288
FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emulation is enabled, attackers can send crafted smartcard cache requests with NULL lookup-name pointers to trigger strlen() on a null pointer, causing client process termination.
CVE-2026-67291
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-byte server-controlled declared fragment size but does not verify it fits within the remaining received buffer before allocating and copying that many bytes. A malicious RDP server can send a short fragment with an oversized declared size, causing the client to read beyond the allocated buffer, resulting in an out-of-bounds read and client crash.
CVE-2026-67301
FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders. When AsyncUpdate is enabled (e.g., xfreerdp /async-update), update_message_PolygonSC() and update_message_PolygonCB() allocate a fresh points array but copy point data from the address of the order structure instead of from polygonSC->points / polygonCB->points, resulting in a client-side out-of-bounds read. A malicious or compromised RDP server sending crafted PolygonSC/PolygonCB update orders can trigger memory disclosure or a client crash.
Update packages.
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the server-declared alloc_hint rather than the actual StubLength about to be written. A malicious TS Gateway can send a PTYPE_RESPONSE with a small alloc_hint and a much larger frag_length, causing Stream_Write to copy attacker-controlled stub data beyond the 4096-byte pdu->s buffer. This can crash the client and may permit code execution through heap corruption. This issue is fixed in version 3.27.0.
FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emulation is enabled, attackers can send crafted smartcard cache requests with NULL lookup-name pointers to trigger strlen() on a null pointer, causing client process termination.
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-byte server-controlled declared fragment size but does not verify it fits within the remaining received buffer before allocating and copying that many bytes. A malicious RDP server can send a short fragment with an oversized declared size, causing the client to read beyond the allocated buffer, resulting in an out-of-bounds read and client crash.
FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders. When AsyncUpdate is enabled (e.g., xfreerdp /async-update), update_message_PolygonSC() and update_message_PolygonCB() allocate a fresh points array but copy point data from the address of the order structure instead of from polygonSC->points / polygonCB->points, resulting in a client-side out-of-bounds read. A malicious or compromised RDP server sending crafted PolygonSC/PolygonCB update orders can trigger memory disclosure or a client crash.
N/A
SRPMS
- freerdp-2.11.7-7.el9_8.6.src.rpm
MD5: 3e4cd127cd3d596b5d781580ea900df0
SHA-256: 882165223f23c71e5a6555169f97af0d88959ab69eebef8cc0ef5b3d6eea7420
Size: 7.06 MB
Asianux Server 9 for x86_64
- freerdp-2.11.7-7.el9_8.6.x86_64.rpm
MD5: c65d5790c2eb5cac18748fa4c67870e2
SHA-256: c24fe55edc033016edb46af34335b38d4498d192864dde3e26ff78b0db106ef3
Size: 113.14 kB - freerdp-devel-2.11.7-7.el9_8.6.i686.rpm
MD5: 438ec9253e2345d3f10cecb28658dcb5
SHA-256: 8252998b299a32f46e8468118806f005c2c5ebed5509c8e2321ee35b10b21737
Size: 177.20 kB - freerdp-devel-2.11.7-7.el9_8.6.x86_64.rpm
MD5: dc4e762e3268b3198903995b97f19b58
SHA-256: d6ca35ba9a301ba79d4049adfca33104c4ef7b7d0c7a42824e083c3dd9b0c9aa
Size: 177.21 kB - freerdp-libs-2.11.7-7.el9_8.6.i686.rpm
MD5: be3e7a6ccd1f460faf66475ba8ce3ce9
SHA-256: 6f88971fff276afc7eb17797a37088b883f38c040821bf517b93072a384692d6
Size: 852.72 kB - freerdp-libs-2.11.7-7.el9_8.6.x86_64.rpm
MD5: 3daf121b851235351cdb504040fd8f4d
SHA-256: fc3e67f1d40149a020490da23aee855473c33f714381a397bd9a49b8ce084cef
Size: 909.21 kB - libwinpr-2.11.7-7.el9_8.6.i686.rpm
MD5: 7dc7a84abe60d48982a45d4374432f8e
SHA-256: fa566a25bc224f52925c601f9342e7c599a888a8eda0211061afc7e4c3a0176c
Size: 341.28 kB - libwinpr-2.11.7-7.el9_8.6.x86_64.rpm
MD5: e5bc494dc417c3f53e6c58f4298ed247
SHA-256: ea198b06d431e802bf0909c894e44b8da07852685002255768fd2206bec02368
Size: 355.58 kB - libwinpr-devel-2.11.7-7.el9_8.6.i686.rpm
MD5: 6cab7dea8207668851c1268bd9808e02
SHA-256: bbcf099d0e576b9504f314c234912f5e4c7d343beb04b6bfd7c3bd3bd6afcfda
Size: 183.09 kB - libwinpr-devel-2.11.7-7.el9_8.6.x86_64.rpm
MD5: 35143b5d9d3e2204f88252f44feab2a0
SHA-256: 69b331e595414e7602c8919fcfe9d57e66aa2e7058c60e7acda91544dbd10ca8
Size: 183.09 kB