Количество 13
Количество 13
BDU:2026-04155
Уязвимость функции smartcard_unpack_read_size_align() RDP-клиента FreeRDP, позволяющая нарушителю вызвать аварийное завершение работы приложения
ROS-20260615-73-0014
Уязвимость freerdp3
ROS-20260615-73-0013
Уязвимость freerdp
CVE-2026-27015
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a missing bounds check in `smartcard_unpack_read_size_align()` (`libfreerdp/utils/smartcard_pack.c:1703`) allows a malicious RDP server to crash the FreeRDP client via a reachable `WINPR_ASSERT` → `abort()`. The crash occurs in upstream builds where `WITH_VERBOSE_WINPR_ASSERT=ON` (default in FreeRDP 3.22.0 / current WinPR CMake defaults). Smartcard redirection must be explicitly enabled by the user (e.g., `xfreerdp /smartcard`; `/smartcard-logon` implies `/smartcard`). Version 3.23.0 fixes the issue.
CVE-2026-27015
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a missing bounds check in `smartcard_unpack_read_size_align()` (`libfreerdp/utils/smartcard_pack.c:1703`) allows a malicious RDP server to crash the FreeRDP client via a reachable `WINPR_ASSERT` → `abort()`. The crash occurs in upstream builds where `WITH_VERBOSE_WINPR_ASSERT=ON` (default in FreeRDP 3.22.0 / current WinPR CMake defaults). Smartcard redirection must be explicitly enabled by the user (e.g., `xfreerdp /smartcard`; `/smartcard-logon` implies `/smartcard`). Version 3.23.0 fixes the issue.
CVE-2026-27015
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a missing bounds check in `smartcard_unpack_read_size_align()` (`libfreerdp/utils/smartcard_pack.c:1703`) allows a malicious RDP server to crash the FreeRDP client via a reachable `WINPR_ASSERT` → `abort()`. The crash occurs in upstream builds where `WITH_VERBOSE_WINPR_ASSERT=ON` (default in FreeRDP 3.22.0 / current WinPR CMake defaults). Smartcard redirection must be explicitly enabled by the user (e.g., `xfreerdp /smartcard`; `/smartcard-logon` implies `/smartcard`). Version 3.23.0 fixes the issue.
CVE-2026-27015
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...
SUSE-SU-2026:1635-1
Security update for freerdp
SUSE-SU-2026:1634-1
Security update for freerdp
SUSE-SU-2026:1632-1
Security update for freerdp
SUSE-SU-2026:1640-1
Security update for freerdp2
SUSE-SU-2026:1633-1
Security update for freerdp
openSUSE-SU-2026:20632-1
Security update for freerdp2
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-04155 Уязвимость функции smartcard_unpack_read_size_align() RDP-клиента FreeRDP, позволяющая нарушителю вызвать аварийное завершение работы приложения | CVSS3: 6.5 | 0% Низкий | 5 месяцев назад | |
ROS-20260615-73-0014 Уязвимость freerdp3 | CVSS3: 6.5 | 0% Низкий | около 2 месяцев назад | |
ROS-20260615-73-0013 Уязвимость freerdp | CVSS3: 6.5 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-27015 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a missing bounds check in `smartcard_unpack_read_size_align()` (`libfreerdp/utils/smartcard_pack.c:1703`) allows a malicious RDP server to crash the FreeRDP client via a reachable `WINPR_ASSERT` → `abort()`. The crash occurs in upstream builds where `WITH_VERBOSE_WINPR_ASSERT=ON` (default in FreeRDP 3.22.0 / current WinPR CMake defaults). Smartcard redirection must be explicitly enabled by the user (e.g., `xfreerdp /smartcard`; `/smartcard-logon` implies `/smartcard`). Version 3.23.0 fixes the issue. | CVSS3: 6.5 | 0% Низкий | 5 месяцев назад | |
CVE-2026-27015 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a missing bounds check in `smartcard_unpack_read_size_align()` (`libfreerdp/utils/smartcard_pack.c:1703`) allows a malicious RDP server to crash the FreeRDP client via a reachable `WINPR_ASSERT` → `abort()`. The crash occurs in upstream builds where `WITH_VERBOSE_WINPR_ASSERT=ON` (default in FreeRDP 3.22.0 / current WinPR CMake defaults). Smartcard redirection must be explicitly enabled by the user (e.g., `xfreerdp /smartcard`; `/smartcard-logon` implies `/smartcard`). Version 3.23.0 fixes the issue. | CVSS3: 6.5 | 0% Низкий | 5 месяцев назад | |
CVE-2026-27015 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a missing bounds check in `smartcard_unpack_read_size_align()` (`libfreerdp/utils/smartcard_pack.c:1703`) allows a malicious RDP server to crash the FreeRDP client via a reachable `WINPR_ASSERT` → `abort()`. The crash occurs in upstream builds where `WITH_VERBOSE_WINPR_ASSERT=ON` (default in FreeRDP 3.22.0 / current WinPR CMake defaults). Smartcard redirection must be explicitly enabled by the user (e.g., `xfreerdp /smartcard`; `/smartcard-logon` implies `/smartcard`). Version 3.23.0 fixes the issue. | CVSS3: 6.5 | 0% Низкий | 5 месяцев назад | |
CVE-2026-27015 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ... | CVSS3: 6.5 | 0% Низкий | 5 месяцев назад | |
SUSE-SU-2026:1635-1 Security update for freerdp | 3 месяца назад | |||
SUSE-SU-2026:1634-1 Security update for freerdp | 3 месяца назад | |||
SUSE-SU-2026:1632-1 Security update for freerdp | 3 месяца назад | |||
SUSE-SU-2026:1640-1 Security update for freerdp2 | 3 месяца назад | |||
SUSE-SU-2026:1633-1 Security update for freerdp | 3 месяца назад | |||
openSUSE-SU-2026:20632-1 Security update for freerdp2 | 3 месяца назад |
Уязвимостей на страницу