Red Hat Security Advisory: freerdp security update
🔗 CVE IDs covered (13)
📋 Description
CVE-2026-55194 — FreeRDP: FreeRDP: Heap-buffer-overflow allows arbitrary code execution via crafted RPC response CVE-2026-63633 — freerdp: FreeRDP: Arbitrary code execution via heap buffer overflow in Opus audio decode CVE-2026-63652 — FreeRDP: FreeRDP: Denial of Service and heap corruption via malformed RDP audio PDU CVE-2026-67288 — FreeRDP: FreeRDP: Denial of Service via crafted smartcard cache requests CVE-2026-67291 — FreeRDP: FreeRDP: Denial of Service via heap out-of-bounds read CVE-2026-67296 — FreeRDP: FreeRDP: Denial of Service due to RDPEI message processing CVE-2026-67297 — FreeRDP: FreeRDP: Resource exhaustion due to oversized chunked HTTP responses CVE-2026-67298 — FreeRDP: FreeRDP: Denial of Service via integer underflow in RAIL channel handling CVE-2026-67301 — FreeRDP: FreeRDP: Memory disclosure or denial of service via crafted RDP update orders CVE-2026-67304 — FreeRDP: FreeRDP: Denial of Service via null pointer dereference in smartcard cleanup CVE-2026-69159 — FreeRDP: FreeRDP: Out-of-bounds read leads to denial of service and information disclosure CVE-2026-73241 — FreeRDP: FreeRDP: Authentication bypass via incorrect RDSTLS PDU handling CVE-2026-73242 — FreeRDP: FreeRDP: Out-of-bounds memory access in Kerberos decryption
🎯 Affected products67
- Red Hat Enterprise Linux AppStream (v. 10)
- Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- freerdp-2:3.10.3-12.el10_2.10.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- freerdp-2:3.10.3-12.el10_2.10.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
- freerdp-2:3.10.3-12.el10_2.10.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
- freerdp-2:3.10.3-12.el10_2.10.src as a component of Red Hat Enterprise Linux AppStream (v. 10)
- freerdp-2:3.10.3-12.el10_2.10.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- freerdp-debuginfo-2:3.10.3-12.el10_2.10.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- freerdp-debuginfo-2:3.10.3-12.el10_2.10.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- freerdp-debuginfo-2:3.10.3-12.el10_2.10.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
- freerdp-debuginfo-2:3.10.3-12.el10_2.10.ppc64le as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- freerdp-debuginfo-2:3.10.3-12.el10_2.10.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
- freerdp-debuginfo-2:3.10.3-12.el10_2.10.s390x as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- freerdp-debuginfo-2:3.10.3-12.el10_2.10.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- freerdp-debuginfo-2:3.10.3-12.el10_2.10.x86_64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- freerdp-debugsource-2:3.10.3-12.el10_2.10.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- freerdp-debugsource-2:3.10.3-12.el10_2.10.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- freerdp-debugsource-2:3.10.3-12.el10_2.10.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
- freerdp-debugsource-2:3.10.3-12.el10_2.10.ppc64le as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- freerdp-debugsource-2:3.10.3-12.el10_2.10.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
- freerdp-debugsource-2:3.10.3-12.el10_2.10.s390x as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- freerdp-debugsource-2:3.10.3-12.el10_2.10.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- freerdp-debugsource-2:3.10.3-12.el10_2.10.x86_64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- freerdp-devel-2:3.10.3-12.el10_2.10.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- freerdp-devel-2:3.10.3-12.el10_2.10.ppc64le as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- freerdp-devel-2:3.10.3-12.el10_2.10.s390x as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- freerdp-devel-2:3.10.3-12.el10_2.10.x86_64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- freerdp-libs-2:3.10.3-12.el10_2.10.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- freerdp-libs-2:3.10.3-12.el10_2.10.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
- freerdp-libs-2:3.10.3-12.el10_2.10.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
- +37 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this vulnerability, avoid connecting through untrusted TS Gateways (RD Gateways) or disable gateway parameters (such as omitting `/g:` in `xfreerdp`) to force direct RDP connections and bypass RPC response parsing. Workaround: To mitigate this vulnerability, disable audio redirection on client connections by omitting audio parameters (such as `/sound` or `/audio`) in `xfreerdp` to bypass client-side DSP audio decoding. Workaround: To mitigate this issue, disable audio redirection on the FreeRDP server configuration if remote audio capability is not required. Workaround: If smartcard redirection/emulation is unused, do not enable it (omit /smartcard and /smartcard-logon, or start with /smartcard:off). Only connect FreeRDP clients to trusted RDP endpoints Workaround: To mitigate this issue, avoid connecting FreeRDP clients to untrusted or potentially malicious RDP servers. If such connections are required, run the client on a dedicated, isolated system so a client crash is contained and does not impact other workloads. Workaround: To mitigate this do not expose FreeRDP server/proxy/shadow (freerdp-shadow-cli / freerdp-proxy) to untrusted networks—allow only trusted clients via firewall, or disable those services if unused. Workaround: To mitigate this issue, FreeRDP clients should only connect to trusted Remote Desktop Gateway endpoints. Avoiding connections to untrusted or potentially compromised gateways will prevent exposure to malicious servers that could exploit this vulnerability by sending oversized chunked HTTP responses. Workaround: To mitigate this issue do not expose FreeRDP server/proxy/shadow (freerdp-shadow-cli / freerdp-proxy) to untrusted networks—allow only trusted clients via firewall, or disable those services if unused. Workaround: To mitigate this issue, avoid enabling the `async-update` feature when using FreeRDP clients. This feature is not enabled by default. If `xfreerdp` is used, ensure the `/async-update` command-line option is not specified. Disabling this feature may impact performance in certain RDP sessions where asynchronous updates are beneficial. Workaround: To mitigate this issue, disable smartcard redirection in FreeRDP client configurations if smartcard functionality is not required. This can typically be achieved by launching the `xfreerdp` client without the `/smartcard` option, or by explicitly setting `/smartcard:no` if a configuration file is used. Disabling smartcard redirection will prevent the use of smartcard devices with FreeRDP sessions. Workaround: To mitigate this vulnerability, disable RDP planar graphics codec acceleration in client settings or force alternative graphics rendering modes (such as standard RemoteFX or H.264) when connecting to untrusted RDP servers. Workaround: Do not enable RDSTLS server authentication (RdstlsSecurity); it is disabled by default. If FreeRDP is deployed as an RDP server with RDSTLS enabled, disable RdstlsSecurity Workaround: Use FreeRDP with Kerberos/NLA only against trusted RDP peers. As a client, avoid connecting to untrusted RDP servers; as a server, restrict inbound RDP to trusted clients using host firewall rules or network segmentation.
🔗 References (16)
- selfhttps://access.redhat.com/errata/RHSA-2026:61378
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2509986
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2509994
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2510001
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2510010
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2510029
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2510034
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2510041
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2514346
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2514349
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2519822
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2519824
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2519826
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2519828
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_61378.json