Описание
ELSA-2026-36203: freerdp security update (IMPORTANT)
[2:3.10.3-12.6]
- Backport several CVE fixes (CVE-2026-40033, CVE-2026-44420, CVE-2026-44421, CVE-2026-44422, CVE-2026-45700) Resolves: RHEL-186978, RHEL-186967, RHEL-186958, RHEL-186950, RHEL-186093
[2:3.10.3-12.5]
- Lock appWindow to fix use-after-free in RAIL mode (CVE-2026-25952) Resolves: RHEL-159848
[2:3.10.3-12.4]
- Fix double free in xf_rail_window_common cleanup (CVE-2026-26986)
- Fix clipboard use-after-free during auto-reconnect (CVE-2026-25997)
- Fix heap-buffer-overflow in bitmap_cache_put (CVE-2026-29775)
- Add DSP format checks (CVE-2026-31884)
- Fix DSP array bounds checks (CVE-2026-31883)
- Fix DSP array bounds checks (CVE-2026-31885)
- Update PERSISTENT_CACHE_ENTRY::size after realloc (CVE-2026-33987)
- Update CLEAR_GLYPH_ENTRY::count after alloc (CVE-2026-33985)
- Use winpr_aligned_calloc in persistent cache (CVE-2026-33982) Resolves: RHEL-159804, RHEL-159660, RHEL-161034, RHEL-161469 Resolves: RHEL-161505, RHEL-161072, RHEL-163654, RHEL-168462, RHEL-162931
Обновленные пакеты
Oracle Linux 10
Oracle Linux aarch64
freerdp
3.10.3-12.el10_2.6
freerdp-devel
3.10.3-12.el10_2.6
freerdp-libs
3.10.3-12.el10_2.6
freerdp-server
3.10.3-12.el10_2.6
libwinpr
3.10.3-12.el10_2.6
libwinpr-devel
3.10.3-12.el10_2.6
Oracle Linux x86_64
freerdp
3.10.3-12.el10_2.6
freerdp-devel
3.10.3-12.el10_2.6
freerdp-libs
3.10.3-12.el10_2.6
freerdp-server
3.10.3-12.el10_2.6
libwinpr
3.10.3-12.el10_2.6
libwinpr-devel
3.10.3-12.el10_2.6
Ссылки на источники
Связанные уязвимости
FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps coordinates to UINT16_MAX but performs copy operations using unclamped cache entry dimensions, enabling malicious RDP servers to trigger large out-of-bounds writes and potentially achieve remote code execution or client crash.
FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps coordinates to UINT16_MAX but performs copy operations using unclamped cache entry dimensions, enabling malicious RDP servers to trigger large out-of-bounds writes and potentially achieve remote code execution or client crash.
FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps coordinates to UINT16_MAX but performs copy operations using unclamped cache entry dimensions, enabling malicious RDP servers to trigger large out-of-bounds writes and potentially achieve remote code execution or client crash.