Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:10951 - Security Advisory
Issued:
2026-04-27
Updated:
2026-04-27

RHSA-2026:10951 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: freerdp security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for freerdp is now available for Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.

Security Fix(es):

  • freerdp: FreeRDP heap-use-after-free (CVE-2026-22856)
  • freerdp: FreeRDP heap-buffer-overflow (CVE-2026-22854)
  • freerdp: FreeRDP heap-buffer-overflow (CVE-2026-22852)
  • freerdp: FreeRDP: Denial of Service via FastGlyph parsing buffer overflow (CVE-2026-23732)
  • freerdp: FreeRDP: Denial of Service via use-after-free in AUDIN format renegotiation (CVE-2026-24676)
  • freerdp: FreeRDP has a heap-use-after-free in video_timer (CVE-2026-24491)
  • freerdp: FreeRDP has a NULL Pointer Dereference in rdp_write_logon_info_v2() (CVE-2026-23948)
  • freerdp: FreeRDP has a Heap-use-after-free in play_thread (CVE-2026-24684)
  • freerdp: FreeRDP has a heap-buffer-overflow in urb_select_interface (CVE-2026-24679)
  • freerdp: FreeRDP has a Heap-use-after-free in urb_select_interface (CVE-2026-24675)
  • freerdp: FreeRDP: Arbitrary code execution via crafted Remote Desktop Protocol (RDP) server messages (CVE-2026-31806)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.6 x86_64
  • Red Hat Enterprise Linux Server - AUS 8.6 x86_64
  • Red Hat Enterprise Linux Server - TUS 8.6 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.6 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.6 x86_64

Fixes

  • BZ - 2429650 - CVE-2026-22856 freerdp: FreeRDP heap-use-after-free
  • BZ - 2429652 - CVE-2026-22854 freerdp: FreeRDP heap-buffer-overflow
  • BZ - 2429654 - CVE-2026-22852 freerdp: FreeRDP heap-buffer-overflow
  • BZ - 2430881 - CVE-2026-23732 freerdp: FreeRDP: Denial of Service via FastGlyph parsing buffer overflow
  • BZ - 2438201 - CVE-2026-24676 freerdp: FreeRDP: Denial of Service via use-after-free in AUDIN format renegotiation
  • BZ - 2438202 - CVE-2026-24491 freerdp: FreeRDP has a heap-use-after-free in video_timer
  • BZ - 2438207 - CVE-2026-23948 freerdp: FreeRDP has a NULL Pointer Dereference in rdp_write_logon_info_v2()
  • BZ - 2438208 - CVE-2026-24684 freerdp: FreeRDP has a Heap-use-after-free in play_thread
  • BZ - 2438217 - CVE-2026-24679 freerdp: FreeRDP has a heap-buffer-overflow in urb_select_interface
  • BZ - 2438221 - CVE-2026-24675 freerdp: FreeRDP has a Heap-use-after-free in urb_select_interface
  • BZ - 2447376 - CVE-2026-31806 freerdp: FreeRDP: Arbitrary code execution via crafted Remote Desktop Protocol (RDP) server messages

CVEs

  • CVE-2026-22852
  • CVE-2026-22854
  • CVE-2026-22856
  • CVE-2026-23732
  • CVE-2026-23948
  • CVE-2026-24491
  • CVE-2026-24675
  • CVE-2026-24676
  • CVE-2026-24679
  • CVE-2026-24684
  • CVE-2026-31806

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.6

SRPM
freerdp-2.2.0-7.el8_6.5.src.rpm SHA-256: b91fc38f7520cde69e0140ecc3dcf928df91411f74c332e91bffc5fd37d3ec3d
x86_64
freerdp-2.2.0-7.el8_6.5.x86_64.rpm SHA-256: 90e3c69fbf47393cd246a6242ade8c23c487f86937deb6af524e5a981ee2e736
freerdp-debuginfo-2.2.0-7.el8_6.5.i686.rpm SHA-256: 0d8f4bbdd5dcfff9c8511c4a0b7dfaa59c856cc4d5ab688e6ced44127079e494
freerdp-debuginfo-2.2.0-7.el8_6.5.x86_64.rpm SHA-256: 1a25e41cbf7628a3baafa557a8c1a675476f91282cea4bb4349ac0e07e668a44
freerdp-debugsource-2.2.0-7.el8_6.5.i686.rpm SHA-256: 7e49197ecb015b6d6e02ac0dbe636973fe47b9879e66356737635a7bcbbdaa95
freerdp-debugsource-2.2.0-7.el8_6.5.x86_64.rpm SHA-256: 0e2315a4bfc69441323309b103c2aef3183b612f2caf3638dc76f0d0f4b4821c
freerdp-libs-2.2.0-7.el8_6.5.i686.rpm SHA-256: aa6eaffec091d00fd32a117d348fb0d4ecf7bddafb8f226b583793da5cfa0d32
freerdp-libs-2.2.0-7.el8_6.5.x86_64.rpm SHA-256: 56bb6b4d21bd206c96884fd0d917cf1513dc77525e07272983031ce720515cca
freerdp-libs-debuginfo-2.2.0-7.el8_6.5.i686.rpm SHA-256: cec269992ffa0905e9eb85fce480fd2fee89d1840b1eebfea8789b2e8addd4b7
freerdp-libs-debuginfo-2.2.0-7.el8_6.5.x86_64.rpm SHA-256: b3c27e0408d3f5ba7a718df1f19723936fa60b1779ffa01c00f9aa01210f79b7
libwinpr-2.2.0-7.el8_6.5.i686.rpm SHA-256: 11f837f435ca7a2c899e24046c22db6148d505b07e177156802f2034b0334ae0
libwinpr-2.2.0-7.el8_6.5.x86_64.rpm SHA-256: 5fbefbdac65ba31b1fcb54095deae60b315e677fe16745ef0368192012e93a7c
libwinpr-debuginfo-2.2.0-7.el8_6.5.i686.rpm SHA-256: 70d698a0916d049341b31e8b6add53c612da2c0e2481e9c202cc7d6919d79fcb
libwinpr-debuginfo-2.2.0-7.el8_6.5.x86_64.rpm SHA-256: 7f4c38471493ef42251388b4a12b66988d1344b14ef5efb12bb992977b58e8ba
libwinpr-devel-2.2.0-7.el8_6.5.i686.rpm SHA-256: 54e5595aef0cf4aeba704dd138ae1ad5728a319252658b2ab44b304a69b96705
libwinpr-devel-2.2.0-7.el8_6.5.x86_64.rpm SHA-256: 8412f280c1bb330222e51c270ea3d66f2e7c50657f9d899ef3cf8e5fd6f19201

Red Hat Enterprise Linux Server - AUS 8.6

SRPM
freerdp-2.2.0-7.el8_6.5.src.rpm SHA-256: b91fc38f7520cde69e0140ecc3dcf928df91411f74c332e91bffc5fd37d3ec3d
x86_64
freerdp-2.2.0-7.el8_6.5.x86_64.rpm SHA-256: 90e3c69fbf47393cd246a6242ade8c23c487f86937deb6af524e5a981ee2e736
freerdp-debuginfo-2.2.0-7.el8_6.5.i686.rpm SHA-256: 0d8f4bbdd5dcfff9c8511c4a0b7dfaa59c856cc4d5ab688e6ced44127079e494
freerdp-debuginfo-2.2.0-7.el8_6.5.x86_64.rpm SHA-256: 1a25e41cbf7628a3baafa557a8c1a675476f91282cea4bb4349ac0e07e668a44
freerdp-debugsource-2.2.0-7.el8_6.5.i686.rpm SHA-256: 7e49197ecb015b6d6e02ac0dbe636973fe47b9879e66356737635a7bcbbdaa95
freerdp-debugsource-2.2.0-7.el8_6.5.x86_64.rpm SHA-256: 0e2315a4bfc69441323309b103c2aef3183b612f2caf3638dc76f0d0f4b4821c
freerdp-libs-2.2.0-7.el8_6.5.i686.rpm SHA-256: aa6eaffec091d00fd32a117d348fb0d4ecf7bddafb8f226b583793da5cfa0d32
freerdp-libs-2.2.0-7.el8_6.5.x86_64.rpm SHA-256: 56bb6b4d21bd206c96884fd0d917cf1513dc77525e07272983031ce720515cca
freerdp-libs-debuginfo-2.2.0-7.el8_6.5.i686.rpm SHA-256: cec269992ffa0905e9eb85fce480fd2fee89d1840b1eebfea8789b2e8addd4b7
freerdp-libs-debuginfo-2.2.0-7.el8_6.5.x86_64.rpm SHA-256: b3c27e0408d3f5ba7a718df1f19723936fa60b1779ffa01c00f9aa01210f79b7
libwinpr-2.2.0-7.el8_6.5.i686.rpm SHA-256: 11f837f435ca7a2c899e24046c22db6148d505b07e177156802f2034b0334ae0
libwinpr-2.2.0-7.el8_6.5.x86_64.rpm SHA-256: 5fbefbdac65ba31b1fcb54095deae60b315e677fe16745ef0368192012e93a7c
libwinpr-debuginfo-2.2.0-7.el8_6.5.i686.rpm SHA-256: 70d698a0916d049341b31e8b6add53c612da2c0e2481e9c202cc7d6919d79fcb
libwinpr-debuginfo-2.2.0-7.el8_6.5.x86_64.rpm SHA-256: 7f4c38471493ef42251388b4a12b66988d1344b14ef5efb12bb992977b58e8ba
libwinpr-devel-2.2.0-7.el8_6.5.i686.rpm SHA-256: 54e5595aef0cf4aeba704dd138ae1ad5728a319252658b2ab44b304a69b96705
libwinpr-devel-2.2.0-7.el8_6.5.x86_64.rpm SHA-256: 8412f280c1bb330222e51c270ea3d66f2e7c50657f9d899ef3cf8e5fd6f19201

Red Hat Enterprise Linux Server - TUS 8.6

SRPM
freerdp-2.2.0-7.el8_6.5.src.rpm SHA-256: b91fc38f7520cde69e0140ecc3dcf928df91411f74c332e91bffc5fd37d3ec3d
x86_64
freerdp-2.2.0-7.el8_6.5.x86_64.rpm SHA-256: 90e3c69fbf47393cd246a6242ade8c23c487f86937deb6af524e5a981ee2e736
freerdp-debuginfo-2.2.0-7.el8_6.5.i686.rpm SHA-256: 0d8f4bbdd5dcfff9c8511c4a0b7dfaa59c856cc4d5ab688e6ced44127079e494
freerdp-debuginfo-2.2.0-7.el8_6.5.x86_64.rpm SHA-256: 1a25e41cbf7628a3baafa557a8c1a675476f91282cea4bb4349ac0e07e668a44
freerdp-debugsource-2.2.0-7.el8_6.5.i686.rpm SHA-256: 7e49197ecb015b6d6e02ac0dbe636973fe47b9879e66356737635a7bcbbdaa95
freerdp-debugsource-2.2.0-7.el8_6.5.x86_64.rpm SHA-256: 0e2315a4bfc69441323309b103c2aef3183b612f2caf3638dc76f0d0f4b4821c
freerdp-libs-2.2.0-7.el8_6.5.i686.rpm SHA-256: aa6eaffec091d00fd32a117d348fb0d4ecf7bddafb8f226b583793da5cfa0d32
freerdp-libs-2.2.0-7.el8_6.5.x86_64.rpm SHA-256: 56bb6b4d21bd206c96884fd0d917cf1513dc77525e07272983031ce720515cca
freerdp-libs-debuginfo-2.2.0-7.el8_6.5.i686.rpm SHA-256: cec269992ffa0905e9eb85fce480fd2fee89d1840b1eebfea8789b2e8addd4b7
freerdp-libs-debuginfo-2.2.0-7.el8_6.5.x86_64.rpm SHA-256: b3c27e0408d3f5ba7a718df1f19723936fa60b1779ffa01c00f9aa01210f79b7
libwinpr-2.2.0-7.el8_6.5.i686.rpm SHA-256: 11f837f435ca7a2c899e24046c22db6148d505b07e177156802f2034b0334ae0
libwinpr-2.2.0-7.el8_6.5.x86_64.rpm SHA-256: 5fbefbdac65ba31b1fcb54095deae60b315e677fe16745ef0368192012e93a7c
libwinpr-debuginfo-2.2.0-7.el8_6.5.i686.rpm SHA-256: 70d698a0916d049341b31e8b6add53c612da2c0e2481e9c202cc7d6919d79fcb
libwinpr-debuginfo-2.2.0-7.el8_6.5.x86_64.rpm SHA-256: 7f4c38471493ef42251388b4a12b66988d1344b14ef5efb12bb992977b58e8ba
libwinpr-devel-2.2.0-7.el8_6.5.i686.rpm SHA-256: 54e5595aef0cf4aeba704dd138ae1ad5728a319252658b2ab44b304a69b96705
libwinpr-devel-2.2.0-7.el8_6.5.x86_64.rpm SHA-256: 8412f280c1bb330222e51c270ea3d66f2e7c50657f9d899ef3cf8e5fd6f19201

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.6

SRPM
freerdp-2.2.0-7.el8_6.5.src.rpm SHA-256: b91fc38f7520cde69e0140ecc3dcf928df91411f74c332e91bffc5fd37d3ec3d
ppc64le
freerdp-2.2.0-7.el8_6.5.ppc64le.rpm SHA-256: 3129b33c85a1ae6a0fcbadfcef0af7310ad6f702fea9d2ddedc16c513fb55784
freerdp-debuginfo-2.2.0-7.el8_6.5.ppc64le.rpm SHA-256: 1582d38cb62a48e7d3e87a177c665705c6361bf1585ab6bcc835613f9fecdf3f
freerdp-debugsource-2.2.0-7.el8_6.5.ppc64le.rpm SHA-256: c2c29e685265226dda2d1f39b78f2d559c5ff323b1a1267be98b1d7a29e0facd
freerdp-libs-2.2.0-7.el8_6.5.ppc64le.rpm SHA-256: 21dfd24aeee6b6b8582bcad312e9e759cc27e33f289aa4c9a96a04f4e4a3e339
freerdp-libs-debuginfo-2.2.0-7.el8_6.5.ppc64le.rpm SHA-256: 524474b23528b5be8e03d6f6a369a4aca9047ee8d7d7ef90d38d5ec75584c802
libwinpr-2.2.0-7.el8_6.5.ppc64le.rpm SHA-256: a43e05f73a002d8a90a3a5adde5fa1813ed4175f6dfd3d2f5d789be7a166640a
libwinpr-debuginfo-2.2.0-7.el8_6.5.ppc64le.rpm SHA-256: 4f53f2930092b41d31ce21f96904ec16ed4d6c695275e6d2cbedf013faae5b77
libwinpr-devel-2.2.0-7.el8_6.5.ppc64le.rpm SHA-256: e29bc1ba81fe44e376af86ca9fe45c3a9e0157576d59be2d0dd79129dbc76dd0

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.6

SRPM
freerdp-2.2.0-7.el8_6.5.src.rpm SHA-256: b91fc38f7520cde69e0140ecc3dcf928df91411f74c332e91bffc5fd37d3ec3d
x86_64
freerdp-2.2.0-7.el8_6.5.x86_64.rpm SHA-256: 90e3c69fbf47393cd246a6242ade8c23c487f86937deb6af524e5a981ee2e736
freerdp-debuginfo-2.2.0-7.el8_6.5.i686.rpm SHA-256: 0d8f4bbdd5dcfff9c8511c4a0b7dfaa59c856cc4d5ab688e6ced44127079e494
freerdp-debuginfo-2.2.0-7.el8_6.5.x86_64.rpm SHA-256: 1a25e41cbf7628a3baafa557a8c1a675476f91282cea4bb4349ac0e07e668a44
freerdp-debugsource-2.2.0-7.el8_6.5.i686.rpm SHA-256: 7e49197ecb015b6d6e02ac0dbe636973fe47b9879e66356737635a7bcbbdaa95
freerdp-debugsource-2.2.0-7.el8_6.5.x86_64.rpm SHA-256: 0e2315a4bfc69441323309b103c2aef3183b612f2caf3638dc76f0d0f4b4821c
freerdp-libs-2.2.0-7.el8_6.5.i686.rpm SHA-256: aa6eaffec091d00fd32a117d348fb0d4ecf7bddafb8f226b583793da5cfa0d32
freerdp-libs-2.2.0-7.el8_6.5.x86_64.rpm SHA-256: 56bb6b4d21bd206c96884fd0d917cf1513dc77525e07272983031ce720515cca
freerdp-libs-debuginfo-2.2.0-7.el8_6.5.i686.rpm SHA-256: cec269992ffa0905e9eb85fce480fd2fee89d1840b1eebfea8789b2e8addd4b7
freerdp-libs-debuginfo-2.2.0-7.el8_6.5.x86_64.rpm SHA-256: b3c27e0408d3f5ba7a718df1f19723936fa60b1779ffa01c00f9aa01210f79b7
libwinpr-2.2.0-7.el8_6.5.i686.rpm SHA-256: 11f837f435ca7a2c899e24046c22db6148d505b07e177156802f2034b0334ae0
libwinpr-2.2.0-7.el8_6.5.x86_64.rpm SHA-256: 5fbefbdac65ba31b1fcb54095deae60b315e677fe16745ef0368192012e93a7c
libwinpr-debuginfo-2.2.0-7.el8_6.5.i686.rpm SHA-256: 70d698a0916d049341b31e8b6add53c612da2c0e2481e9c202cc7d6919d79fcb
libwinpr-debuginfo-2.2.0-7.el8_6.5.x86_64.rpm SHA-256: 7f4c38471493ef42251388b4a12b66988d1344b14ef5efb12bb992977b58e8ba
libwinpr-devel-2.2.0-7.el8_6.5.i686.rpm SHA-256: 54e5595aef0cf4aeba704dd138ae1ad5728a319252658b2ab44b304a69b96705
libwinpr-devel-2.2.0-7.el8_6.5.x86_64.rpm SHA-256: 8412f280c1bb330222e51c270ea3d66f2e7c50657f9d899ef3cf8e5fd6f19201

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility