Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-50747

Опубликовано: 05 авг. 2026
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2026-50747: freerdp security update (IMPORTANT)

[2:3.10.3-12.7]

  • Add codecID checks for CACHE_BITMAP_V3_ORDER (CVE-2026-55827)
  • Fix boundary checks in gdi_Bitmap_Decompress (CVE-2026-55827) Resolves: RHEL-194327

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

freerdp

3.10.3-12.el10_2.7

freerdp-devel

3.10.3-12.el10_2.7

freerdp-libs

3.10.3-12.el10_2.7

freerdp-server

3.10.3-12.el10_2.7

libwinpr

3.10.3-12.el10_2.7

libwinpr-devel

3.10.3-12.el10_2.7

Oracle Linux x86_64

freerdp

3.10.3-12.el10_2.7

freerdp-devel

3.10.3-12.el10_2.7

freerdp-libs

3.10.3-12.el10_2.7

freerdp-server

3.10.3-12.el10_2.7

libwinpr

3.10.3-12.el10_2.7

libwinpr-devel

3.10.3-12.el10_2.7

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.1, FreeRDP clients launched with the non-default /cache:codec:rfx option pass desktop stride and height to RemoteFX decoding for Cache Bitmap V3 data while allocating bitmap->data only for the smaller DstWidth and DstHeight in gdi_Bitmap_Decompress, allowing a malicious RDP server to trigger a heap out-of-bounds write with attacker-controlled offset and content. This issue is fixed in version 3.27.1.

CVSS3: 7.5
redhat
2 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.1, FreeRDP clients launched with the non-default /cache:codec:rfx option pass desktop stride and height to RemoteFX decoding for Cache Bitmap V3 data while allocating bitmap->data only for the smaller DstWidth and DstHeight in gdi_Bitmap_Decompress, allowing a malicious RDP server to trigger a heap out-of-bounds write with attacker-controlled offset and content. This issue is fixed in version 3.27.1.

CVSS3: 7.5
nvd
2 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.1, FreeRDP clients launched with the non-default /cache:codec:rfx option pass desktop stride and height to RemoteFX decoding for Cache Bitmap V3 data while allocating bitmap->data only for the smaller DstWidth and DstHeight in gdi_Bitmap_Decompress, allowing a malicious RDP server to trigger a heap out-of-bounds write with attacker-controlled offset and content. This issue is fixed in version 3.27.1.

CVSS3: 7.5
debian
2 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

CVSS3: 8.8
redos
около 1 месяца назад

Уязвимость freerdp3