Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:2048 - Security Advisory
Issued:
2026-02-05
Updated:
2026-02-05

RHSA-2026:2048 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: freerdp security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for freerdp is now available for Red Hat Enterprise Linux 9.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.

Security Fix(es):

  • freerdp: FreeRDP: Heap buffer overflow leading to denial of service and potential code execution from a malicious server. (CVE-2026-23530)
  • freerdp: FreeRDP: Denial of Service and potential code execution via use-after-free vulnerability (CVE-2026-23884)
  • freerdp: FreeRDP: Arbitrary code execution and denial of service via malicious server (CVE-2026-23883)
  • freerdp: FreeRDP: Heap buffer overflow leads to denial of service and potential code execution (CVE-2026-23533)
  • freerdp: FreeRDP: Heap buffer overflow via crafted RDPGFX surface updates leads to denial of service and potential code execution. (CVE-2026-23531)
  • freerdp: FreeRDP: Arbitrary code execution and denial of service via client-side heap buffer overflow (CVE-2026-23534)
  • freerdp: FreeRDP: Denial of Service and potential code execution via client-side heap buffer overflow (CVE-2026-23532)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 9 s390x
  • Red Hat Enterprise Linux for Power, little endian 9 ppc64le
  • Red Hat Enterprise Linux for ARM 64 9 aarch64
  • Red Hat CodeReady Linux Builder for x86_64 9 x86_64
  • Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le
  • Red Hat CodeReady Linux Builder for ARM 64 9 aarch64
  • Red Hat CodeReady Linux Builder for IBM z Systems 9 s390x

Fixes

  • BZ - 2430877 - CVE-2026-23530 freerdp: FreeRDP: Heap buffer overflow leading to denial of service and potential code execution from a malicious server.
  • BZ - 2430880 - CVE-2026-23884 freerdp: FreeRDP: Denial of Service and potential code execution via use-after-free vulnerability
  • BZ - 2430885 - CVE-2026-23883 freerdp: FreeRDP: Arbitrary code execution and denial of service via malicious server
  • BZ - 2430886 - CVE-2026-23533 freerdp: FreeRDP: Heap buffer overflow leads to denial of service and potential code execution
  • BZ - 2430887 - CVE-2026-23531 freerdp: FreeRDP: Heap buffer overflow via crafted RDPGFX surface updates leads to denial of service and potential code execution.
  • BZ - 2430888 - CVE-2026-23534 freerdp: FreeRDP: Arbitrary code execution and denial of service via client-side heap buffer overflow
  • BZ - 2430891 - CVE-2026-23532 freerdp: FreeRDP: Denial of Service and potential code execution via client-side heap buffer overflow

CVEs

  • CVE-2026-23530
  • CVE-2026-23531
  • CVE-2026-23532
  • CVE-2026-23533
  • CVE-2026-23534
  • CVE-2026-23883
  • CVE-2026-23884

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 9

SRPM
freerdp-2.11.7-1.el9_7.1.src.rpm SHA-256: 8737a124784f218d0578a5c84ae32586f2653e8f4c92e8661e9dab45473ba60d
x86_64
freerdp-2.11.7-1.el9_7.1.x86_64.rpm SHA-256: 5abdd20736c01e1d3d1ffc2e231210f7b0dac1fa01ecf7fc62db3e6022d37fa2
freerdp-debuginfo-2.11.7-1.el9_7.1.i686.rpm SHA-256: 53d08b4ab236a2bf807197fbf62f5a74011c9c9c5a0264ca2fd7b05ddde0f29c
freerdp-debuginfo-2.11.7-1.el9_7.1.x86_64.rpm SHA-256: ca23adce407c7150ceb1221c1a72d4a55fe908ccf0e03a30763825e2cfe6f306
freerdp-debugsource-2.11.7-1.el9_7.1.i686.rpm SHA-256: 537c40cb69ab3b60e696c3b6ef9f0bd69bb2efb9ca023c5c4940eb7c8832ce1b
freerdp-debugsource-2.11.7-1.el9_7.1.x86_64.rpm SHA-256: 26eb9c3a6c8ebdc2e5df20b99cf3db007c6b986822c66c2bbd7708be66ee4a77
freerdp-libs-2.11.7-1.el9_7.1.i686.rpm SHA-256: eefbac289cc18dd979d135c6028ce4525622894366181dc361d1a5fc9b3d3aa2
freerdp-libs-2.11.7-1.el9_7.1.x86_64.rpm SHA-256: 672e2d98ee99ecfd6cf97604802ee32b43b3925d3d69eae078bbb99e15a858d8
freerdp-libs-debuginfo-2.11.7-1.el9_7.1.i686.rpm SHA-256: b35c0957eb839972b0b548669f46c4e129f9434d8a0f0286eaa20423171a1f94
freerdp-libs-debuginfo-2.11.7-1.el9_7.1.x86_64.rpm SHA-256: 475e80b66d9021097cec4772a4d525091b6a101529bc53772613c5f0a8413cb0
libwinpr-2.11.7-1.el9_7.1.i686.rpm SHA-256: 531f1f4d567b4d9c961dd296761f6de45055f8aaa6e5a84e14afa188e4c12541
libwinpr-2.11.7-1.el9_7.1.x86_64.rpm SHA-256: 9f62408b86b1d52ca43f08e4ffeb4f0c4885cee5c205af8b2de9d6e2a5c0f889
libwinpr-debuginfo-2.11.7-1.el9_7.1.i686.rpm SHA-256: dafe5bb471dc0311ca61be9ba790ec99678a8e51de37aec11e1a136a5143bda0
libwinpr-debuginfo-2.11.7-1.el9_7.1.x86_64.rpm SHA-256: 41babed5902d1068014d0d3f7eb8a0edabf214bbbb612bafb69129705b0cce67

Red Hat Enterprise Linux for IBM z Systems 9

SRPM
freerdp-2.11.7-1.el9_7.1.src.rpm SHA-256: 8737a124784f218d0578a5c84ae32586f2653e8f4c92e8661e9dab45473ba60d
s390x
freerdp-2.11.7-1.el9_7.1.s390x.rpm SHA-256: fdec160b55bdaa1229d59a60e05be18382e8419d394d3309fd121baa9c1b0d15
freerdp-debuginfo-2.11.7-1.el9_7.1.s390x.rpm SHA-256: aa179da1fe9ca2b019a7130f7d7f1350cee06aeb1886f3e6397a63cb5e6dada2
freerdp-debugsource-2.11.7-1.el9_7.1.s390x.rpm SHA-256: c7a70cf80fdbfdb1efab96c88fdd80c5d29f454a11498a203308bb335334d14e
freerdp-libs-2.11.7-1.el9_7.1.s390x.rpm SHA-256: 1a9abb1e343cd122f79d95ed507ef8362c9702a2401c932f2974eba972b68499
freerdp-libs-debuginfo-2.11.7-1.el9_7.1.s390x.rpm SHA-256: 905bf6d278f21e503c8cb3b405a94e0606542ee8fff71cce02ec35651e35744c
libwinpr-2.11.7-1.el9_7.1.s390x.rpm SHA-256: 8113fc4d5e526dfe1a4c1baca1b25283581af9b6139f8fd3a4d3edaed84a5ad2
libwinpr-debuginfo-2.11.7-1.el9_7.1.s390x.rpm SHA-256: 75c3957ce457ad6c6b6bfef9c452138b6f949b2b311099200ed1bccdf8ef8a39

Red Hat Enterprise Linux for Power, little endian 9

SRPM
freerdp-2.11.7-1.el9_7.1.src.rpm SHA-256: 8737a124784f218d0578a5c84ae32586f2653e8f4c92e8661e9dab45473ba60d
ppc64le
freerdp-2.11.7-1.el9_7.1.ppc64le.rpm SHA-256: 014c0278957ecd96cf5c900743f219bda4cbc2b2ae4191b0bd700dbd31701b4e
freerdp-debuginfo-2.11.7-1.el9_7.1.ppc64le.rpm SHA-256: c7732ab871103725a75dc5866ca83e603912a2663e30aa3467baa666250fb08c
freerdp-debugsource-2.11.7-1.el9_7.1.ppc64le.rpm SHA-256: e0220aad9101d38eb0e6ca841bf4b86f85d14f66a758aeddbe588889de86fb72
freerdp-libs-2.11.7-1.el9_7.1.ppc64le.rpm SHA-256: 15ef0a57e8eeadb8d6949a082e4d3d9a5c351119e65b27b487cf9d295589d4ab
freerdp-libs-debuginfo-2.11.7-1.el9_7.1.ppc64le.rpm SHA-256: babfa5101c82be6b2fab389fe4ff278c7baef143874182ecf3b8e7e575cbef01
libwinpr-2.11.7-1.el9_7.1.ppc64le.rpm SHA-256: 9fddcde3b84603bb6c69dd26323fa83155c0c9f47790f52b25986cbdff022ccc
libwinpr-debuginfo-2.11.7-1.el9_7.1.ppc64le.rpm SHA-256: 349618a4374a0d76c769fc5d977c6e8e1dabe5a001ab6f1286a9cdc41c01ce64

Red Hat Enterprise Linux for ARM 64 9

SRPM
freerdp-2.11.7-1.el9_7.1.src.rpm SHA-256: 8737a124784f218d0578a5c84ae32586f2653e8f4c92e8661e9dab45473ba60d
aarch64
freerdp-2.11.7-1.el9_7.1.aarch64.rpm SHA-256: 981fc7699e781cac04f78ac74342c0fe6b8342e4c325077d3a2bca771fff8abb
freerdp-debuginfo-2.11.7-1.el9_7.1.aarch64.rpm SHA-256: 05d0b20d30c53fd5a303663db81a3d6dd576341bdb63e2b74501b77b384bcce8
freerdp-debugsource-2.11.7-1.el9_7.1.aarch64.rpm SHA-256: fc508ab962a944af134d66e2b7cc4c31e55c75364903de9fa40e4115b7589362
freerdp-libs-2.11.7-1.el9_7.1.aarch64.rpm SHA-256: ea697a3b872a3207745ce8d6b6d626b18193e7a66caeb806af6f3824c8474cb1
freerdp-libs-debuginfo-2.11.7-1.el9_7.1.aarch64.rpm SHA-256: 208fd7a6e27ebdba449f67718826ebe5493fcd4364a76eeca2bd6c3d9ffc1ffa
libwinpr-2.11.7-1.el9_7.1.aarch64.rpm SHA-256: 26d6bd0d7fc1ee90911ca15b3f59df23c392e4d93a8f79fd03c2629078bc127c
libwinpr-debuginfo-2.11.7-1.el9_7.1.aarch64.rpm SHA-256: ba89f941e676dd921ae270bea560bc44a76c3ce0b827cdd6bb55f0179160b7d0

Red Hat CodeReady Linux Builder for x86_64 9

SRPM
x86_64
freerdp-debuginfo-2.11.7-1.el9_7.1.i686.rpm SHA-256: 53d08b4ab236a2bf807197fbf62f5a74011c9c9c5a0264ca2fd7b05ddde0f29c
freerdp-debuginfo-2.11.7-1.el9_7.1.x86_64.rpm SHA-256: ca23adce407c7150ceb1221c1a72d4a55fe908ccf0e03a30763825e2cfe6f306
freerdp-debugsource-2.11.7-1.el9_7.1.i686.rpm SHA-256: 537c40cb69ab3b60e696c3b6ef9f0bd69bb2efb9ca023c5c4940eb7c8832ce1b
freerdp-debugsource-2.11.7-1.el9_7.1.x86_64.rpm SHA-256: 26eb9c3a6c8ebdc2e5df20b99cf3db007c6b986822c66c2bbd7708be66ee4a77
freerdp-devel-2.11.7-1.el9_7.1.i686.rpm SHA-256: 5f0722e38573dd8ac2cc46e85f5cd01408a18e67a06b00409e7901a0399012af
freerdp-devel-2.11.7-1.el9_7.1.x86_64.rpm SHA-256: 642617fd2e33636c4c60cea5d7a74c7973dd89735b136b8f201d8178f1669943
freerdp-libs-debuginfo-2.11.7-1.el9_7.1.i686.rpm SHA-256: b35c0957eb839972b0b548669f46c4e129f9434d8a0f0286eaa20423171a1f94
freerdp-libs-debuginfo-2.11.7-1.el9_7.1.x86_64.rpm SHA-256: 475e80b66d9021097cec4772a4d525091b6a101529bc53772613c5f0a8413cb0
libwinpr-debuginfo-2.11.7-1.el9_7.1.i686.rpm SHA-256: dafe5bb471dc0311ca61be9ba790ec99678a8e51de37aec11e1a136a5143bda0
libwinpr-debuginfo-2.11.7-1.el9_7.1.x86_64.rpm SHA-256: 41babed5902d1068014d0d3f7eb8a0edabf214bbbb612bafb69129705b0cce67
libwinpr-devel-2.11.7-1.el9_7.1.i686.rpm SHA-256: c9ac1589386ffb0abc09181f1908a93b3e5d1fab393a83706c7ff5b10461633d
libwinpr-devel-2.11.7-1.el9_7.1.x86_64.rpm SHA-256: 74d7e4c674248eba65e28774f40d94f0f9307e72be076d0af85ad349f1f99a8c

Red Hat CodeReady Linux Builder for Power, little endian 9

SRPM
ppc64le
freerdp-debuginfo-2.11.7-1.el9_7.1.ppc64le.rpm SHA-256: c7732ab871103725a75dc5866ca83e603912a2663e30aa3467baa666250fb08c
freerdp-debugsource-2.11.7-1.el9_7.1.ppc64le.rpm SHA-256: e0220aad9101d38eb0e6ca841bf4b86f85d14f66a758aeddbe588889de86fb72
freerdp-devel-2.11.7-1.el9_7.1.ppc64le.rpm SHA-256: 134cff1b68590ea487febfc7469d38a0a54d773f4c7f38e3280bb95628d38f5b
freerdp-libs-debuginfo-2.11.7-1.el9_7.1.ppc64le.rpm SHA-256: babfa5101c82be6b2fab389fe4ff278c7baef143874182ecf3b8e7e575cbef01
libwinpr-debuginfo-2.11.7-1.el9_7.1.ppc64le.rpm SHA-256: 349618a4374a0d76c769fc5d977c6e8e1dabe5a001ab6f1286a9cdc41c01ce64
libwinpr-devel-2.11.7-1.el9_7.1.ppc64le.rpm SHA-256: 1d7232cce9b293886c8277ec16e6380a81c5e0ecb066ffbce41637b3b3737fc6

Red Hat CodeReady Linux Builder for ARM 64 9

SRPM
aarch64
freerdp-debuginfo-2.11.7-1.el9_7.1.aarch64.rpm SHA-256: 05d0b20d30c53fd5a303663db81a3d6dd576341bdb63e2b74501b77b384bcce8
freerdp-debugsource-2.11.7-1.el9_7.1.aarch64.rpm SHA-256: fc508ab962a944af134d66e2b7cc4c31e55c75364903de9fa40e4115b7589362
freerdp-devel-2.11.7-1.el9_7.1.aarch64.rpm SHA-256: 7dc5aa57bab1b15a52b19e02ea70a12f5caba8146889350b9494a852c96a0c5f
freerdp-libs-debuginfo-2.11.7-1.el9_7.1.aarch64.rpm SHA-256: 208fd7a6e27ebdba449f67718826ebe5493fcd4364a76eeca2bd6c3d9ffc1ffa
libwinpr-debuginfo-2.11.7-1.el9_7.1.aarch64.rpm SHA-256: ba89f941e676dd921ae270bea560bc44a76c3ce0b827cdd6bb55f0179160b7d0
libwinpr-devel-2.11.7-1.el9_7.1.aarch64.rpm SHA-256: f06efd310f695f158847bededf123d9a657133be2314464184109db3a1a33eb0

Red Hat CodeReady Linux Builder for IBM z Systems 9

SRPM
s390x
freerdp-debuginfo-2.11.7-1.el9_7.1.s390x.rpm SHA-256: aa179da1fe9ca2b019a7130f7d7f1350cee06aeb1886f3e6397a63cb5e6dada2
freerdp-debugsource-2.11.7-1.el9_7.1.s390x.rpm SHA-256: c7a70cf80fdbfdb1efab96c88fdd80c5d29f454a11498a203308bb335334d14e
freerdp-devel-2.11.7-1.el9_7.1.s390x.rpm SHA-256: 58e012fd65603946b04c7a67d328542135c5b1d29845a25827b9775236b40f07
freerdp-libs-debuginfo-2.11.7-1.el9_7.1.s390x.rpm SHA-256: 905bf6d278f21e503c8cb3b405a94e0606542ee8fff71cce02ec35651e35744c
libwinpr-debuginfo-2.11.7-1.el9_7.1.s390x.rpm SHA-256: 75c3957ce457ad6c6b6bfef9c452138b6f949b2b311099200ed1bccdf8ef8a39
libwinpr-devel-2.11.7-1.el9_7.1.s390x.rpm SHA-256: bd155a41b7330096644ee1a54c76c8fce72dc1ef721ca5f2dd8bd17627618904

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility