freerdp-2.11.7-7.el9_8.8
エラータID: AXSA:2026-2009:32
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.
Security Fix(es):
* FreeRDP: FreeRDP: Denial of Service via crafted Surface Bits command (CVE-2026-91954)
* FreeRDP: FreeRDP: Remote code execution via heap buffer overflow in Server Redirection PDU (CVE-2026-91964)
* FreeRDP: FreeRDP: Denial of Service via out-of-bounds read in URBDRC channel (CVE-2026-91956)
* FreeRDP: FreeRDP: Remote code execution via uninitialized heap memory disclosure (CVE-2026-91963)
* FreeRDP: FreeRDP: Denial of Service due to buffer over-read in RPC gateway (CVE-2026-91959)
* FreeRDP: FreeRDP: Heap buffer overflow via oversized LB_LOAD_BALANCE_INFO routing token can lead to heap corruption. (CVE-2026-91953)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-91953
FreeRDP versions before 3.31.0 contain a heap buffer overflow vulnerability in nego_send_negotiation_request() that fails to validate the LB_LOAD_BALANCE_INFO field length before writing to a fixed 512-byte buffer. A malicious RDP server or man-in-the-middle can send a Server Redirection PDU with an oversized LB_LOAD_BALANCE_INFO value to overflow the buffer with attacker-controlled content, causing denial of service or heap corruption before authentication completes.
CVE-2026-91954
FreeRDP before 3.31.0 contains a null pointer dereference vulnerability in gdi_surface_bits when processing Surface Bits commands with NSCodec codec ID. A malicious RDP server can crash a FreeRDP client by sending a crafted Surface Bits command claiming to use NSCodec, even when the codec is disabled.
CVE-2026-91956
FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the URBDRC channel's func_get_ep_desc function that indexes interface arrays by position instead of protocol field InterfaceNumber. A malicious RDP server can send a crafted SELECT_CONFIGURATION message with permuted InterfaceNumber values to read past allocated heap memory and crash the client.
CVE-2026-91959
FreeRDP before 3.31.0 contains a buffer over-read vulnerability in the rts_read_result function within the RPC gateway transport parser. Attackers can send a malicious BIND_ACK PDU with a truncated result entry to trigger an out-of-bounds read causing process abort.
CVE-2026-91963
FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.
CVE-2026-91964
FreeRDP versions before 3.31.0 contain a heap-based buffer overflow in nego_send_negotiation_request when processing Server Redirection PDU messages with attacker-controlled LoadBalanceInfo fields. A malicious RDP server can trigger the overflow by sending an arbitrary-length field that gets written to a fixed 512-byte buffer without validation, causing client crashes or potential code execution when chained with memory disclosure.
Update packages.
FreeRDP versions before 3.31.0 contain a heap buffer overflow vulnerability in nego_send_negotiation_request() that fails to validate the LB_LOAD_BALANCE_INFO field length before writing to a fixed 512-byte buffer. A malicious RDP server or man-in-the-middle can send a Server Redirection PDU with an oversized LB_LOAD_BALANCE_INFO value to overflow the buffer with attacker-controlled content, causing denial of service or heap corruption before authentication completes.
FreeRDP before 3.31.0 contains a null pointer dereference vulnerability in gdi_surface_bits when processing Surface Bits commands with NSCodec codec ID. A malicious RDP server can crash a FreeRDP client by sending a crafted Surface Bits command claiming to use NSCodec, even when the codec is disabled.
FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the URBDRC channel's func_get_ep_desc function that indexes interface arrays by position instead of protocol field InterfaceNumber. A malicious RDP server can send a crafted SELECT_CONFIGURATION message with permuted InterfaceNumber values to read past allocated heap memory and crash the client.
FreeRDP before 3.31.0 contains a buffer over-read vulnerability in the rts_read_result function within the RPC gateway transport parser. Attackers can send a malicious BIND_ACK PDU with a truncated result entry to trigger an out-of-bounds read causing process abort.
FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.
FreeRDP versions before 3.31.0 contain a heap-based buffer overflow in nego_send_negotiation_request when processing Server Redirection PDU messages with attacker-controlled LoadBalanceInfo fields. A malicious RDP server can trigger the overflow by sending an arbitrary-length field that gets written to a fixed 512-byte buffer without validation, causing client crashes or potential code execution when chained with memory disclosure.
N/A
SRPMS
- freerdp-2.11.7-7.el9_8.8.src.rpm
MD5: a90f9ff1865f794e642aad3169289dcb
SHA-256: 8dff6434c9cb75b07344bc511dd277a8333c7c907b688d727115097bb6c53d70
Size: 7.07 MB
Asianux Server 9 for x86_64
- freerdp-2.11.7-7.el9_8.8.x86_64.rpm
MD5: 437ba33dd78f15d3b2743d5265826538
SHA-256: 99d2cb53a88c86dad564b4a44f56e45b034dc123eb5957d75eb72baf16f9e4e7
Size: 113.56 kB - freerdp-devel-2.11.7-7.el9_8.8.i686.rpm
MD5: ee2451eeb5fede29e2494f93b5b2534f
SHA-256: 625f8dd7c2e98d096f7d514f63c444010116c0ec503758198328146d1ab397fa
Size: 177.72 kB - freerdp-devel-2.11.7-7.el9_8.8.x86_64.rpm
MD5: 199caae5ea742924ebdec0c30d6864ee
SHA-256: 80563a3e4f263525b309ec34a26d2fcc0365046580c8c1f378cc1b65a2d6d16f
Size: 177.64 kB - freerdp-libs-2.11.7-7.el9_8.8.i686.rpm
MD5: 157f975fd0e0e12c567cf8a3dbfd871f
SHA-256: c1cc16f248aae9c935f021ef80fb3dfc56152d1155be20886c55719a90c17306
Size: 853.83 kB - freerdp-libs-2.11.7-7.el9_8.8.x86_64.rpm
MD5: 6ba5b38e09c482330b4cda029dafd9eb
SHA-256: 2d42a4e9a3eaf3451d66f9ceef5eb23e622a913a459228c42a71f6e5df0b7187
Size: 909.16 kB - libwinpr-2.11.7-7.el9_8.8.i686.rpm
MD5: 9c3f28365083e03a42560f78020befe3
SHA-256: 00a6579f1a9c9b534af1473086df555b5ea3142d9cdffcbab4950bb2a09554ef
Size: 341.72 kB - libwinpr-2.11.7-7.el9_8.8.x86_64.rpm
MD5: f1eeba9161bec6d4af555c0811a64a60
SHA-256: 917dd89c8537909270ec7c551e482757faf03d9d283dfdd77320da7d5ace7986
Size: 356.98 kB - libwinpr-devel-2.11.7-7.el9_8.8.i686.rpm
MD5: 662afff02a79afa0feb9b0b74068c001
SHA-256: b6051ba79077173b0d571ec06318b321a9c63d01b82b10ed9505d3951a01f334
Size: 183.53 kB - libwinpr-devel-2.11.7-7.el9_8.8.x86_64.rpm
MD5: 454f2968d2caed0628416506321e95d5
SHA-256: 78dd28a4b37c14e38aec1868a23591e20808d9c4c6d6f48ac4366ebcfc71dab7
Size: 183.55 kB