rpm package
almalinux/freerdp-server
pkg:rpm/almalinux/freerdp-server
Vulnerabilities (67)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-69159 | — | < 2:3.10.3-12.el10_2.10 | 2:3.10.3-12.el10_2.10 | Aug 19, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67306. Reason: This candidate is a duplicate of CVE-2026-67306. Notes: All CVE users should reference CVE-2026-67306 instead of this candidate. | ||
| CVE-2026-63652 | Med | 6.5 | < 2:3.10.3-12.el10_2.10 | 2:3.10.3-12.el10_2.10 | Aug 19, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv_formats in channels/rdpsnd/server/rdpsnd_main.c frees context->client_formats on a malformed Client Audio Formats PDU without clearing the owning pointer or num_client_formats. An | |
| CVE-2026-63633 | Cri | 9.8 | < 2:3.10.3-12.el10_2.10 | 2:3.10.3-12.el10_2.10 | Aug 19, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, freerdp_dsp_decode_opus in libfreerdp/codec/dsp.c calls Stream_EnsureRemainingCapacity on context->common.buffer even though opus_decode writes decoded PCM into the caller-supplied out stream. A mal | |
| CVE-2026-55194 | Cri | 9.8 | < 2:3.10.3-12.el10_2.10 | 2:3.10.3-12.el10_2.10 | Aug 19, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the server-declared alloc_hint rather than the actual StubLength about to | |
| CVE-2026-55193 | Hig | 8.8 | < 2:3.10.3-12.el10_2.11 | 2:3.10.3-12.el10_2.11 | Aug 19, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients using TS Gateway accept a server-controlled max_xmit_frag value in libfreerdp/core/gateway/rpc_bind.c without bounding it to the 4088-byte ReceiveFragment allocation. A malicious gat | |
| CVE-2026-73242 | Cri | 9.1 | < 2:3.10.3-12.el10_2.10 | 2:3.10.3-12.el10_2.10 | Aug 11, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos/kerberos.c kerberos_DecryptMessage function fails to bound the peer-controlled GSS Wrap-token EC field before using it with RRC in IOV pointer offsets, allowin | |
| CVE-2026-73241 | Hig | 7.5 | < 2:3.10.3-12.el10_2.10 | 2:3.10.3-12.el10_2.10 | Aug 11, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-side RDSTLS in libfreerdp/core/rdstls.c accepts an attacker-supplied RDSTLS_TYPE_CAPABILITIES PDU while rdstls_server_authenticate is waiting for RDSTLS_TYPE_AUTHREQ, leaving resultCo | |
| CVE-2026-68580 | Hig | 7.5 | < 2:3.10.3-12.el10_2.8 | 2:3.10.3-12.el10_2.8 | Aug 2, 2026 | FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can supply a malicious FramesPerPacket | |
| CVE-2026-67304 | Hig | 7.5 | < 2:3.10.3-12.el10_2.10 | 2:3.10.3-12.el10_2.10 | Aug 1, 2026 | FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails. Attackers can send malformed smartcard IRP requests with non-zero cReaders and truncated reader-state data to crash the process vi | |
| CVE-2026-67301 | Hig | 7.5 | < 2:3.10.3-12.el10_2.10 | 2:3.10.3-12.el10_2.10 | Aug 1, 2026 | FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders. When AsyncUpdate is enabled (e.g., xfreerdp /async-update), update_message_PolygonSC() and update_message_PolygonCB() alloca | |
| CVE-2026-67299 | Hig | 7.5 | < 2:3.10.3-12.el10_2.8 | 2:3.10.3-12.el10_2.8 | Aug 1, 2026 | FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled (e.g. xfreerdp /async-update). In update_message_WindowIcon() a shallow CopyMemory() overwrites a freshly allocated lParam->iconInf | |
| CVE-2026-67298 | Hig | 7.5 | < 2:3.10.3-12.el10_2.10 | 2:3.10.3-12.el10_2.10 | Aug 1, 2026 | FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_handle_messages() in channels/rail/server/rail_main.c). When processing a RAIL PDU header, the code subtracts RAIL_PDU_HEADER_LENGTH from the peer-controlled or | |
| CVE-2026-67297 | Hig | 7.5 | < 2:3.10.3-12.el10_2.10 | 2:3.10.3-12.el10_2.10 | Aug 1, 2026 | FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resourc | |
| CVE-2026-67296 | Hig | 7.5 | < 2:3.10.3-12.el10_2.10 | 2:3.10.3-12.el10_2.10 | Aug 1, 2026 | FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large declared body length to force exc | |
| CVE-2026-67291 | Hig | 7.5 | < 2:3.10.3-12.el10_2.10 | 2:3.10.3-12.el10_2.10 | Aug 1, 2026 | FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-byte server-controlled declared fragm | |
| CVE-2026-67289 | Cri | 9.8 | < 2:3.10.3-12.el10_2.8 | 2:3.10.3-12.el10_2.8 | Aug 1, 2026 | FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written | |
| CVE-2026-67288 | Hig | 7.5 | < 2:3.10.3-12.el10_2.10 | 2:3.10.3-12.el10_2.10 | Aug 1, 2026 | FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emulation is enabled, attackers can send craft | |
| CVE-2026-64624 | Hig | 7.8 | < 2:3.10.3-12.el10_2.8 | 2:3.10.3-12.el10_2.8 | Jul 20, 2026 | FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP files with /rdp2tcp, /cert:ignore, or /drive options to execute arbitrary command | |
| CVE-2026-64621 | Hig | 7.3 | < 2:3.10.3-12.el10_2.8 | 2:3.10.3-12.el10_2.8 | Jul 20, 2026 | FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double-free vulnerability in freerdp_client_rdp_file_apply_to_settings() (client/common/file.c) when parsing the selectedmonitors field of a .rdp connection file. The MonitorIds array is allocated through the settings | |
| CVE-2026-64620 | Cri | 9.8 | < 2:3.10.3-12.el10_2.8 | 2:3.10.3-12.el10_2.8 | Jul 20, 2026 | FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypto/crypto.c). The function writes the modular-exponentiation result into the caller's output buffer via BN_bn2bin() and only afterward checks output_length > out |
- CVE-2026-69159Aug 19, 2026affected < 2:3.10.3-12.el10_2.10fixed 2:3.10.3-12.el10_2.10
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67306. Reason: This candidate is a duplicate of CVE-2026-67306. Notes: All CVE users should reference CVE-2026-67306 instead of this candidate.
- affected < 2:3.10.3-12.el10_2.10fixed 2:3.10.3-12.el10_2.10
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv_formats in channels/rdpsnd/server/rdpsnd_main.c frees context->client_formats on a malformed Client Audio Formats PDU without clearing the owning pointer or num_client_formats. An
- affected < 2:3.10.3-12.el10_2.10fixed 2:3.10.3-12.el10_2.10
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, freerdp_dsp_decode_opus in libfreerdp/codec/dsp.c calls Stream_EnsureRemainingCapacity on context->common.buffer even though opus_decode writes decoded PCM into the caller-supplied out stream. A mal
- affected < 2:3.10.3-12.el10_2.10fixed 2:3.10.3-12.el10_2.10
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the server-declared alloc_hint rather than the actual StubLength about to
- affected < 2:3.10.3-12.el10_2.11fixed 2:3.10.3-12.el10_2.11
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients using TS Gateway accept a server-controlled max_xmit_frag value in libfreerdp/core/gateway/rpc_bind.c without bounding it to the 4088-byte ReceiveFragment allocation. A malicious gat
- affected < 2:3.10.3-12.el10_2.10fixed 2:3.10.3-12.el10_2.10
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos/kerberos.c kerberos_DecryptMessage function fails to bound the peer-controlled GSS Wrap-token EC field before using it with RRC in IOV pointer offsets, allowin
- affected < 2:3.10.3-12.el10_2.10fixed 2:3.10.3-12.el10_2.10
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-side RDSTLS in libfreerdp/core/rdstls.c accepts an attacker-supplied RDSTLS_TYPE_CAPABILITIES PDU while rdstls_server_authenticate is waiting for RDSTLS_TYPE_AUTHREQ, leaving resultCo
- affected < 2:3.10.3-12.el10_2.8fixed 2:3.10.3-12.el10_2.8
FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can supply a malicious FramesPerPacket
- affected < 2:3.10.3-12.el10_2.10fixed 2:3.10.3-12.el10_2.10
FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails. Attackers can send malformed smartcard IRP requests with non-zero cReaders and truncated reader-state data to crash the process vi
- affected < 2:3.10.3-12.el10_2.10fixed 2:3.10.3-12.el10_2.10
FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders. When AsyncUpdate is enabled (e.g., xfreerdp /async-update), update_message_PolygonSC() and update_message_PolygonCB() alloca
- affected < 2:3.10.3-12.el10_2.8fixed 2:3.10.3-12.el10_2.8
FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled (e.g. xfreerdp /async-update). In update_message_WindowIcon() a shallow CopyMemory() overwrites a freshly allocated lParam->iconInf
- affected < 2:3.10.3-12.el10_2.10fixed 2:3.10.3-12.el10_2.10
FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_handle_messages() in channels/rail/server/rail_main.c). When processing a RAIL PDU header, the code subtracts RAIL_PDU_HEADER_LENGTH from the peer-controlled or
- affected < 2:3.10.3-12.el10_2.10fixed 2:3.10.3-12.el10_2.10
FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resourc
- affected < 2:3.10.3-12.el10_2.10fixed 2:3.10.3-12.el10_2.10
FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large declared body length to force exc
- affected < 2:3.10.3-12.el10_2.10fixed 2:3.10.3-12.el10_2.10
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-byte server-controlled declared fragm
- affected < 2:3.10.3-12.el10_2.8fixed 2:3.10.3-12.el10_2.8
FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written
- affected < 2:3.10.3-12.el10_2.10fixed 2:3.10.3-12.el10_2.10
FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emulation is enabled, attackers can send craft
- affected < 2:3.10.3-12.el10_2.8fixed 2:3.10.3-12.el10_2.8
FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP files with /rdp2tcp, /cert:ignore, or /drive options to execute arbitrary command
- affected < 2:3.10.3-12.el10_2.8fixed 2:3.10.3-12.el10_2.8
FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double-free vulnerability in freerdp_client_rdp_file_apply_to_settings() (client/common/file.c) when parsing the selectedmonitors field of a .rdp connection file. The MonitorIds array is allocated through the settings
- affected < 2:3.10.3-12.el10_2.8fixed 2:3.10.3-12.el10_2.8
FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypto/crypto.c). The function writes the modular-exponentiation result into the caller's output buffer via BN_bn2bin() and only afterward checks output_length > out
Page 1 of 4