Red Hat Security Advisory: freerdp security update
🔗 CVE IDs covered (10)
📋 Description
CVE-2026-25952 — freerdp: FreeRDP: Denial of service due to use-after-free vulnerability
CVE-2026-25997 — freerdp: FreeRDP: Denial of service via heap use-after-free during auto-reconnect
CVE-2026-26986 — freerdp: FreeRDP: Denial of Service via double free vulnerability during disconnect
CVE-2026-29775 — freerdp: FreeRDP has a heap-buffer-overflow in bitmap_cache_put via OOB cacheId
CVE-2026-31883 — freerdp: FreeRDP: Denial of Service via crafted audio data in RDP
CVE-2026-31884 — freerdp: FreeRDP has a division-by-zero in ADPCM decoders when nBlockAlign is 0
CVE-2026-31885 — freerdp: FreeRDP has an out-of-bounds read in ADPCM decoders due to missing predictor/step_index bounds checks
CVE-2026-33982 — FreeRDP: FreeRDP: Information disclosure and denial of service via heap-buffer-overflow read
CVE-2026-33985 — FreeRDP: FreeRDP: Information disclosure via heap memory out of bounds read
CVE-2026-33987 — FreeRDP: FreeRDP: Memory corruption vulnerability allows denial of service or arbitrary code execution
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2026:20605
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2442764
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2442768
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2442782
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2447379
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2447383
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2447385
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2447386
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2453217
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2453218
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2453226
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_20605.json