[CLSA-2026:1773928998] freerdp: Fix of 8 CVEs
Type:
security
Severity:
Critical
Release date:
2026-03-19 14:03:22 UTC
Description:
- CVE-2026-25941: validate bitmapDataLength in RDPGFX wire_to_surface_2 - CVE-2026-25942: bounds check execResult in xf_rail_server_execute_result - CVE-2026-25952: use-after-free in X11 RAIL window handling - CVE-2026-25953: use-after-free in xf_AppUpdateWindowFromSurface - CVE-2026-25954: use-after-free in xf_rail_server_local_move_size - CVE-2026-25959: use-after-free in clipboard format data response - CVE-2026-26986: use-after-free in rail_window_free on title allocation failure - CVE-2026-27951: integer overflow in Stream_EnsureCapacity
Updated packages:
  • freerdp-2.1.1-5.el7_9.tuxcare.els15.x86_64.rpm
    sha:745a995432629b255b3c146fe14be0a5da9c437ee2a3b4be599b3a42ae0c87a7
  • freerdp-devel-2.1.1-5.el7_9.tuxcare.els15.i686.rpm
    sha:0b5f55fe89254a6bf001e31e3bdc93d9ac0010a39e309460a65538277ba89008
  • freerdp-devel-2.1.1-5.el7_9.tuxcare.els15.x86_64.rpm
    sha:a00297359f565df6ddd6ec518e2a66a9e712e5f1e40e761478066f406f8a5092
  • freerdp-libs-2.1.1-5.el7_9.tuxcare.els15.i686.rpm
    sha:d9bb8a444c5d43af99a8a7bb836f45e16915717969cca970eeecdde3179de882
  • freerdp-libs-2.1.1-5.el7_9.tuxcare.els15.x86_64.rpm
    sha:709949d6ff752a3652328f14c654d9626f05db9a4103649f6728537b760aab02
  • libwinpr-2.1.1-5.el7_9.tuxcare.els15.i686.rpm
    sha:deac24ab910d395622205559606317af98d300b7d4d3a4394bb10d42fedb555c
  • libwinpr-2.1.1-5.el7_9.tuxcare.els15.x86_64.rpm
    sha:290a9dee7396b4eb7637815e431e94e205d3fc386ec9e82ce735fd4adf86cbe4
  • libwinpr-devel-2.1.1-5.el7_9.tuxcare.els15.i686.rpm
    sha:b580b378fcad2b48311e0698f82fe6c8a7346cf2682a86ce8e1930ad303051c3
  • libwinpr-devel-2.1.1-5.el7_9.tuxcare.els15.x86_64.rpm
    sha:862c76a8e293e657969477150273fd8a9a330c5958f964677f0507d1861d5504
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.