Red Hat Security Advisory: freerdp security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2026-55194 — FreeRDP: FreeRDP: Heap-buffer-overflow allows arbitrary code execution via crafted RPC response CVE-2026-67288 — FreeRDP: FreeRDP: Denial of Service via crafted smartcard cache requests CVE-2026-67291 — FreeRDP: FreeRDP: Denial of Service via heap out-of-bounds read CVE-2026-67301 — FreeRDP: FreeRDP: Memory disclosure or denial of service via crafted RDP update orders
🎯 Affected products67
- Red Hat Enterprise Linux AppStream (v. 9)
- Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
- freerdp-2:2.11.7-7.el9_8.6.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- freerdp-2:2.11.7-7.el9_8.6.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
- freerdp-2:2.11.7-7.el9_8.6.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
- freerdp-2:2.11.7-7.el9_8.6.src as a component of Red Hat Enterprise Linux AppStream (v. 9)
- freerdp-2:2.11.7-7.el9_8.6.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- freerdp-debuginfo-2:2.11.7-7.el9_8.6.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- freerdp-debuginfo-2:2.11.7-7.el9_8.6.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
- freerdp-debuginfo-2:2.11.7-7.el9_8.6.i686 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- freerdp-debuginfo-2:2.11.7-7.el9_8.6.i686 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
- freerdp-debuginfo-2:2.11.7-7.el9_8.6.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
- freerdp-debuginfo-2:2.11.7-7.el9_8.6.ppc64le as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
- freerdp-debuginfo-2:2.11.7-7.el9_8.6.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
- freerdp-debuginfo-2:2.11.7-7.el9_8.6.s390x as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
- freerdp-debuginfo-2:2.11.7-7.el9_8.6.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- freerdp-debuginfo-2:2.11.7-7.el9_8.6.x86_64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
- freerdp-debugsource-2:2.11.7-7.el9_8.6.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- freerdp-debugsource-2:2.11.7-7.el9_8.6.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
- freerdp-debugsource-2:2.11.7-7.el9_8.6.i686 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- freerdp-debugsource-2:2.11.7-7.el9_8.6.i686 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
- freerdp-debugsource-2:2.11.7-7.el9_8.6.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
- freerdp-debugsource-2:2.11.7-7.el9_8.6.ppc64le as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
- freerdp-debugsource-2:2.11.7-7.el9_8.6.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
- freerdp-debugsource-2:2.11.7-7.el9_8.6.s390x as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
- freerdp-debugsource-2:2.11.7-7.el9_8.6.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- freerdp-debugsource-2:2.11.7-7.el9_8.6.x86_64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
- freerdp-devel-2:2.11.7-7.el9_8.6.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
- freerdp-devel-2:2.11.7-7.el9_8.6.i686 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
- freerdp-devel-2:2.11.7-7.el9_8.6.ppc64le as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
- +37 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this vulnerability, avoid connecting through untrusted TS Gateways (RD Gateways) or disable gateway parameters (such as omitting `/g:` in `xfreerdp`) to force direct RDP connections and bypass RPC response parsing. Workaround: If smartcard redirection/emulation is unused, do not enable it (omit /smartcard and /smartcard-logon, or start with /smartcard:off). Only connect FreeRDP clients to trusted RDP endpoints Workaround: To mitigate this issue, avoid connecting FreeRDP clients to untrusted or potentially malicious RDP servers. If such connections are required, run the client on a dedicated, isolated system so a client crash is contained and does not impact other workloads. Workaround: To mitigate this issue, avoid enabling the `async-update` feature when using FreeRDP clients. This feature is not enabled by default. If `xfreerdp` is used, ensure the `/async-update` command-line option is not specified. Disabling this feature may impact performance in certain RDP sessions where asynchronous updates are beneficial.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:61379
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2509994
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2510001
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2510010
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2519824
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_61379.json