Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:19811 - Security Advisory
Issued:
2026-05-20
Updated:
2026-05-20

RHSA-2026:19811 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: freerdp security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for freerdp is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.

Security Fix(es):

  • freerdp: FreeRDP: Denial of service due to use-after-free vulnerability (CVE-2026-25952)
  • freerdp: FreeRDP: Denial of Service via double free vulnerability during disconnect (CVE-2026-26986)
  • freerdp: FreeRDP: Denial of Service via endless blocking loop in Stream_EnsureCapacity (CVE-2026-27951)
  • freerdp: FreeRDP has a heap-buffer-overflow in bitmap_cache_put via OOB cacheId (CVE-2026-29775)
  • freerdp: FreeRDP has an out-of-bounds read in ADPCM decoders due to missing predictor/step_index bounds checks (CVE-2026-31885)
  • freerdp: FreeRDP has a division-by-zero in ADPCM decoders when `nBlockAlign` is 0 (CVE-2026-31884)
  • freerdp: FreeRDP: Denial of Service via crafted audio data in RDP (CVE-2026-31883)
  • FreeRDP: FreeRDP: Information disclosure via heap memory out of bounds read (CVE-2026-33985)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4 x86_64
  • Red Hat Enterprise Linux Server - AUS 8.4 x86_64

Fixes

  • BZ - 2442768 - CVE-2026-25952 freerdp: FreeRDP: Denial of service due to use-after-free vulnerability
  • BZ - 2442782 - CVE-2026-26986 freerdp: FreeRDP: Denial of Service via double free vulnerability during disconnect
  • BZ - 2442783 - CVE-2026-27951 freerdp: FreeRDP: Denial of Service via endless blocking loop in Stream_EnsureCapacity
  • BZ - 2447379 - CVE-2026-29775 freerdp: FreeRDP has a heap-buffer-overflow in bitmap_cache_put via OOB cacheId
  • BZ - 2447383 - CVE-2026-31885 freerdp: FreeRDP has an out-of-bounds read in ADPCM decoders due to missing predictor/step_index bounds checks
  • BZ - 2447385 - CVE-2026-31884 freerdp: FreeRDP has a division-by-zero in ADPCM decoders when `nBlockAlign` is 0
  • BZ - 2447386 - CVE-2026-31883 freerdp: FreeRDP: Denial of Service via crafted audio data in RDP
  • BZ - 2453217 - CVE-2026-33985 FreeRDP: FreeRDP: Information disclosure via heap memory out of bounds read

CVEs

  • CVE-2026-25952
  • CVE-2026-26986
  • CVE-2026-27951
  • CVE-2026-29775
  • CVE-2026-31883
  • CVE-2026-31884
  • CVE-2026-31885
  • CVE-2026-33985

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4

SRPM
freerdp-2.2.0-14.el8_4.src.rpm SHA-256: 527cbeeef2e290758a29a38f0cc2b3ca5d44078724a8cbaa967691ee9f0dc42c
x86_64
freerdp-2.2.0-14.el8_4.x86_64.rpm SHA-256: 37dd5aec72c864b8b5411e27ff21466daf86a6a290fa4260ae85d1a65dd42555
freerdp-debuginfo-2.2.0-14.el8_4.i686.rpm SHA-256: cf2a48db1b894d479279de779e2a5333fcf33d7813ed301d64411948ea27631a
freerdp-debuginfo-2.2.0-14.el8_4.x86_64.rpm SHA-256: 02f1d6b3f940e52015c6e1f3ddd07a98ee8313af80d96fc4403491409ffb93b1
freerdp-debugsource-2.2.0-14.el8_4.i686.rpm SHA-256: 76a9e3d23fc5f61a17f068cb2b1f5949906236030078080b9b6628dfdc898636
freerdp-debugsource-2.2.0-14.el8_4.x86_64.rpm SHA-256: b9ea519dfc2562138c0771c15cdd9bc4c21c50614badd0432f5ca6675de87201
freerdp-libs-2.2.0-14.el8_4.i686.rpm SHA-256: dd1fbaff9a16749b8b02187c00e736ce83813abb04e34dfe76dcf8b4ad53124d
freerdp-libs-2.2.0-14.el8_4.x86_64.rpm SHA-256: 8471d140b1067134171054d807a75b1f5e599eb619ae36e6f58792a68fdcafbf
freerdp-libs-debuginfo-2.2.0-14.el8_4.i686.rpm SHA-256: f35b16b6ab46b581edd9e053857d447ccbd48f8cd5e28c61468937b94460b90a
freerdp-libs-debuginfo-2.2.0-14.el8_4.x86_64.rpm SHA-256: 1afe2a320c427b36865b5c9fbc533e778a48bccba08efc7117a0439ee4361af4
libwinpr-2.2.0-14.el8_4.i686.rpm SHA-256: e72aef47f845b162f25626324acae945c34b5889be9aed4efdb65302fb77cadf
libwinpr-2.2.0-14.el8_4.x86_64.rpm SHA-256: f70720cc7998bf40e6a60bf849c9db2b912399735e55db278f6ee50e859af91b
libwinpr-debuginfo-2.2.0-14.el8_4.i686.rpm SHA-256: d1ac4bb995da332955053ed0e096de9dba15a6951c99a12c3a56c7094620b2f7
libwinpr-debuginfo-2.2.0-14.el8_4.x86_64.rpm SHA-256: 36bd3ac988de1e9561497bd5e3e08ee4f1044596abeabe010ea15aca9df9fb20
libwinpr-devel-2.2.0-14.el8_4.i686.rpm SHA-256: bb503574467e49660cf64ba19cca19a59ff128db3f1efa57d1b2889521f087ee
libwinpr-devel-2.2.0-14.el8_4.x86_64.rpm SHA-256: 547a43f139ee0ff67eed6888a07400f64c408839661771553ca3d23b1a0fdf76

Red Hat Enterprise Linux Server - AUS 8.4

SRPM
freerdp-2.2.0-14.el8_4.src.rpm SHA-256: 527cbeeef2e290758a29a38f0cc2b3ca5d44078724a8cbaa967691ee9f0dc42c
x86_64
freerdp-2.2.0-14.el8_4.x86_64.rpm SHA-256: 37dd5aec72c864b8b5411e27ff21466daf86a6a290fa4260ae85d1a65dd42555
freerdp-debuginfo-2.2.0-14.el8_4.i686.rpm SHA-256: cf2a48db1b894d479279de779e2a5333fcf33d7813ed301d64411948ea27631a
freerdp-debuginfo-2.2.0-14.el8_4.x86_64.rpm SHA-256: 02f1d6b3f940e52015c6e1f3ddd07a98ee8313af80d96fc4403491409ffb93b1
freerdp-debugsource-2.2.0-14.el8_4.i686.rpm SHA-256: 76a9e3d23fc5f61a17f068cb2b1f5949906236030078080b9b6628dfdc898636
freerdp-debugsource-2.2.0-14.el8_4.x86_64.rpm SHA-256: b9ea519dfc2562138c0771c15cdd9bc4c21c50614badd0432f5ca6675de87201
freerdp-libs-2.2.0-14.el8_4.i686.rpm SHA-256: dd1fbaff9a16749b8b02187c00e736ce83813abb04e34dfe76dcf8b4ad53124d
freerdp-libs-2.2.0-14.el8_4.x86_64.rpm SHA-256: 8471d140b1067134171054d807a75b1f5e599eb619ae36e6f58792a68fdcafbf
freerdp-libs-debuginfo-2.2.0-14.el8_4.i686.rpm SHA-256: f35b16b6ab46b581edd9e053857d447ccbd48f8cd5e28c61468937b94460b90a
freerdp-libs-debuginfo-2.2.0-14.el8_4.x86_64.rpm SHA-256: 1afe2a320c427b36865b5c9fbc533e778a48bccba08efc7117a0439ee4361af4
libwinpr-2.2.0-14.el8_4.i686.rpm SHA-256: e72aef47f845b162f25626324acae945c34b5889be9aed4efdb65302fb77cadf
libwinpr-2.2.0-14.el8_4.x86_64.rpm SHA-256: f70720cc7998bf40e6a60bf849c9db2b912399735e55db278f6ee50e859af91b
libwinpr-debuginfo-2.2.0-14.el8_4.i686.rpm SHA-256: d1ac4bb995da332955053ed0e096de9dba15a6951c99a12c3a56c7094620b2f7
libwinpr-debuginfo-2.2.0-14.el8_4.x86_64.rpm SHA-256: 36bd3ac988de1e9561497bd5e3e08ee4f1044596abeabe010ea15aca9df9fb20
libwinpr-devel-2.2.0-14.el8_4.i686.rpm SHA-256: bb503574467e49660cf64ba19cca19a59ff128db3f1efa57d1b2889521f087ee
libwinpr-devel-2.2.0-14.el8_4.x86_64.rpm SHA-256: 547a43f139ee0ff67eed6888a07400f64c408839661771553ca3d23b1a0fdf76

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility