[CLSA-2026:1771011128] freerdp: Fix of 2 CVEs
Type:
security
Severity:
Critical
Release date:
2026-02-13 19:32:12 UTC
Description:
- CVE-2026-22857: fix heap use-after-free in irp_thread_func when serial_process_irp fails - CVE-2026-23530: fix heap buffer overflow in planar bitmap decompression due to missing nSrcWidth/nSrcHeight validation
Updated packages:
  • freerdp-2.1.1-5.el7_9.tuxcare.els10.x86_64.rpm
    sha:8411dd1baf539b1ea83bf44e726a8e3ab843bcc08380a16a9b64b06064926cea
  • freerdp-devel-2.1.1-5.el7_9.tuxcare.els10.i686.rpm
    sha:fc2317af68adb45ae424d04538e1bcac6eadf0c72b9fdc09b6ac8d33cf3c1148
  • freerdp-devel-2.1.1-5.el7_9.tuxcare.els10.x86_64.rpm
    sha:34ee2e2ad0426cefb91bcf86fbd9c753b1474e59d05b46e7bf2b931335c16929
  • freerdp-libs-2.1.1-5.el7_9.tuxcare.els10.i686.rpm
    sha:033667490bd6fd999241a9fbfe6f70b7436b35272ef5c6f35e1c5e0592e8847f
  • freerdp-libs-2.1.1-5.el7_9.tuxcare.els10.x86_64.rpm
    sha:91e7722fb275f0155733e43a2b0dd137da35626c999df3aedf446686ff6c55db
  • libwinpr-2.1.1-5.el7_9.tuxcare.els10.i686.rpm
    sha:3929ae0ee943570cea5460c4285f7761b10c5ba4542af8d191b623015ac5c137
  • libwinpr-2.1.1-5.el7_9.tuxcare.els10.x86_64.rpm
    sha:a658f639ec4abbb943c9733dc2c0f9ca5cc250562c96107e44fa73e30a19c8cc
  • libwinpr-devel-2.1.1-5.el7_9.tuxcare.els10.i686.rpm
    sha:48bcc5ea99bb288180c806498cb89d2a47cd6488ecde14f8db7da909caa998db
  • libwinpr-devel-2.1.1-5.el7_9.tuxcare.els10.x86_64.rpm
    sha:0f14d0384e06eaf67028f697d2b787f7dc5cc3264b934753bc0b29722d5b5117
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.