Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:1217-1

Опубликовано: 08 апр. 2026
Источник: suse-cvrf

Описание

Security update for freerdp

This update for freerdp fixes the following issue:

  • CVE-2026-24684: Heap-use-after-free in play_thread (bsc#1257991).

Список пакетов

SUSE Linux Enterprise Module for Package Hub 15 SP7
uwac0-0-devel-2.11.2-150600.4.21.1
openSUSE Leap 15.6
freerdp-2.11.2-150600.4.21.1
freerdp-devel-2.11.2-150600.4.21.1
freerdp-proxy-2.11.2-150600.4.21.1
freerdp-server-2.11.2-150600.4.21.1
freerdp-wayland-2.11.2-150600.4.21.1
libfreerdp2-2-2.11.2-150600.4.21.1
libuwac0-0-2.11.2-150600.4.21.1
libwinpr2-2-2.11.2-150600.4.21.1
uwac0-0-devel-2.11.2-150600.4.21.1
winpr-devel-2.11.2-150600.4.21.1

Описание

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, the RDPSND async playback thread can process queued PDUs after the channel is closed and internal state is freed, leading to a use after free in rdpsnd_treat_wave. This vulnerability is fixed in 3.22.0.


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP7:uwac0-0-devel-2.11.2-150600.4.21.1
openSUSE Leap 15.6:freerdp-2.11.2-150600.4.21.1
openSUSE Leap 15.6:freerdp-devel-2.11.2-150600.4.21.1
openSUSE Leap 15.6:freerdp-proxy-2.11.2-150600.4.21.1

Ссылки