freerdp-2.11.7-12.el8_10

エラータID: AXSA:2026-1756:28

Release date: 
Friday, September 4, 2026 - 13:54
Subject: 
freerdp-2.11.7-12.el8_10
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.

Security Fix(es):

* FreeRDP: FreeRDP: Memory disclosure or denial of service via crafted RDP update orders (CVE-2026-67301)
* FreeRDP: FreeRDP: Denial of Service via crafted smartcard cache requests (CVE-2026-67288)
* FreeRDP: FreeRDP: Denial of Service via heap out-of-bounds read (CVE-2026-67291)
* FreeRDP: FreeRDP: Heap-buffer-overflow allows arbitrary code execution via crafted RPC response (CVE-2026-55194)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-55194
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the server-declared alloc_hint rather than the actual StubLength about to be written. A malicious TS Gateway can send a PTYPE_RESPONSE with a small alloc_hint and a much larger frag_length, causing Stream_Write to copy attacker-controlled stub data beyond the 4096-byte pdu->s buffer. This can crash the client and may permit code execution through heap corruption. This issue is fixed in version 3.27.0.
CVE-2026-67288
FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emulation is enabled, attackers can send crafted smartcard cache requests with NULL lookup-name pointers to trigger strlen() on a null pointer, causing client process termination.
CVE-2026-67291
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-byte server-controlled declared fragment size but does not verify it fits within the remaining received buffer before allocating and copying that many bytes. A malicious RDP server can send a short fragment with an oversized declared size, causing the client to read beyond the allocated buffer, resulting in an out-of-bounds read and client crash.
CVE-2026-67301
FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders. When AsyncUpdate is enabled (e.g., xfreerdp /async-update), update_message_PolygonSC() and update_message_PolygonCB() allocate a fresh points array but copy point data from the address of the order structure instead of from polygonSC->points / polygonCB->points, resulting in a client-side out-of-bounds read. A malicious or compromised RDP server sending crafted PolygonSC/PolygonCB update orders can trigger memory disclosure or a client crash.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. freerdp-2.11.7-12.el8_10.src.rpm
    MD5: 2de768d7e4f3a67e6c03feb41c28d8a2
    SHA-256: 69af96084f946a30b6d01c0b7422800aa093414e947f9cc3c1183e67ecc15ea5
    Size: 7.05 MB

Asianux Server 8 for x86_64
  1. freerdp-2.11.7-12.el8_10.x86_64.rpm
    MD5: 048c38cb72fe372016f69250176a78a1
    SHA-256: c342b24fa137b4951dc1253cf84576f6baea13c9d6b5b1b20808abbd7447e5a7
    Size: 120.57 kB
  2. freerdp-devel-2.11.7-12.el8_10.i686.rpm
    MD5: dceb67950c8e8ce6e1740ccfa8c6f8a8
    SHA-256: 90ffb2b7f63f6538448bac12a1866da8ca9e813e888687475ae0134e9a723ca3
    Size: 148.75 kB
  3. freerdp-devel-2.11.7-12.el8_10.x86_64.rpm
    MD5: 9f3a7d509236f494e725ec7292c315fd
    SHA-256: 387e2d2ec475a84644a086d12e8584776cb010e5f0c794ce9f61adafb249e50c
    Size: 148.78 kB
  4. freerdp-libs-2.11.7-12.el8_10.i686.rpm
    MD5: fa25a9ac45431357a99da86c40d91d19
    SHA-256: 17c5a7257a108175a74c5d611c995c54b75d2e081ee359024947b94b2a325307
    Size: 878.72 kB
  5. freerdp-libs-2.11.7-12.el8_10.x86_64.rpm
    MD5: 2abaae61c756b954715efd7dfc29e738
    SHA-256: 2151891269caf5297da53e646210eccdd386711756b1a6ba894005fb4022646e
    Size: 931.35 kB
  6. libwinpr-2.11.7-12.el8_10.i686.rpm
    MD5: e76edcc54204d0c619c91b473dbfdb13
    SHA-256: 24719018c84069155aea148621fbc120488490eabbb992fa4c9b87bbca33d0a2
    Size: 364.47 kB
  7. libwinpr-2.11.7-12.el8_10.x86_64.rpm
    MD5: 62a87b06d13543024c51305b8cbd4577
    SHA-256: e18ded1a985522d2da0042e770a5366af5cdf8667f36306f0dc9dd2d9e0adb4e
    Size: 380.86 kB
  8. libwinpr-devel-2.11.7-12.el8_10.i686.rpm
    MD5: 73fa6d3832fdbb93146754143e4ec63f
    SHA-256: 7435cc102041471eec72072f872c32775ecc3b4cc9868fca2528f4d9cffe0fc2
    Size: 176.93 kB
  9. libwinpr-devel-2.11.7-12.el8_10.x86_64.rpm
    MD5: 06ee5d4d133e924f6b257be482ad2aa6
    SHA-256: 2ea56262ee40f3946c2ffb43ae9a4fffcc631ee5a607f3b5132a532cde094891
    Size: 176.91 kB