Описание
Security update for freerdp2
This update for freerdp2 fixes the following issues:
- Fix the CVE-2026-24684 patch, as the previous version wrongly deleted a check for an error condition (bsc#1257991).
Список пакетов
SUSE Linux Enterprise Module for Package Hub 15 SP7
winpr2-devel-2.11.7-150700.3.17.1
SUSE Linux Enterprise Workstation Extension 15 SP7
freerdp2-2.11.7-150700.3.17.1
freerdp2-devel-2.11.7-150700.3.17.1
freerdp2-proxy-2.11.7-150700.3.17.1
freerdp2-server-2.11.7-150700.3.17.1
libfreerdp2-2-2.11.7-150700.3.17.1
libwinpr2-2-2.11.7-150700.3.17.1
winpr2-devel-2.11.7-150700.3.17.1
Ссылки
- Link for SUSE-SU-2026:1313-1
- E-Mail link for SUSE-SU-2026:1313-1
- SUSE Security Ratings
- SUSE Bug 1257991
- SUSE CVE CVE-2026-24684 page
Описание
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, the RDPSND async playback thread can process queued PDUs after the channel is closed and internal state is freed, leading to a use after free in rdpsnd_treat_wave. This vulnerability is fixed in 3.22.0.
Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP7:winpr2-devel-2.11.7-150700.3.17.1
SUSE Linux Enterprise Workstation Extension 15 SP7:freerdp2-2.11.7-150700.3.17.1
SUSE Linux Enterprise Workstation Extension 15 SP7:freerdp2-devel-2.11.7-150700.3.17.1
SUSE Linux Enterprise Workstation Extension 15 SP7:freerdp2-proxy-2.11.7-150700.3.17.1
Ссылки
- CVE-2026-24684
- SUSE Bug 1257991