Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:2222 - Security Advisory
Issued:
2026-02-09
Updated:
2026-02-09

RHSA-2026:2222 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: freerdp security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for freerdp is now available for Red Hat Enterprise Linux 10.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.

Security Fix(es):

  • freerdp: FreeRDP: Heap buffer overflow leading to denial of service and potential code execution from a malicious server. (CVE-2026-23530)
  • freerdp: FreeRDP: Denial of Service and potential code execution via use-after-free vulnerability (CVE-2026-23884)
  • freerdp: FreeRDP: Arbitrary code execution and denial of service via malicious server (CVE-2026-23883)
  • freerdp: FreeRDP: Heap buffer overflow leads to denial of service and potential code execution (CVE-2026-23533)
  • freerdp: FreeRDP: Heap buffer overflow via crafted RDPGFX surface updates leads to denial of service and potential code execution. (CVE-2026-23531)
  • freerdp: FreeRDP: Arbitrary code execution and denial of service via client-side heap buffer overflow (CVE-2026-23534)
  • freerdp: FreeRDP: Denial of Service and potential code execution via client-side heap buffer overflow (CVE-2026-23532)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 10 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 10 s390x
  • Red Hat Enterprise Linux for Power, little endian 10 ppc64le
  • Red Hat Enterprise Linux for ARM 64 10 aarch64
  • Red Hat CodeReady Linux Builder for x86_64 10 x86_64
  • Red Hat CodeReady Linux Builder for Power, little endian 10 ppc64le
  • Red Hat CodeReady Linux Builder for ARM 64 10 aarch64
  • Red Hat CodeReady Linux Builder for IBM z Systems 10 s390x

Fixes

  • BZ - 2430877 - CVE-2026-23530 freerdp: FreeRDP: Heap buffer overflow leading to denial of service and potential code execution from a malicious server.
  • BZ - 2430880 - CVE-2026-23884 freerdp: FreeRDP: Denial of Service and potential code execution via use-after-free vulnerability
  • BZ - 2430885 - CVE-2026-23883 freerdp: FreeRDP: Arbitrary code execution and denial of service via malicious server
  • BZ - 2430886 - CVE-2026-23533 freerdp: FreeRDP: Heap buffer overflow leads to denial of service and potential code execution
  • BZ - 2430887 - CVE-2026-23531 freerdp: FreeRDP: Heap buffer overflow via crafted RDPGFX surface updates leads to denial of service and potential code execution.
  • BZ - 2430888 - CVE-2026-23534 freerdp: FreeRDP: Arbitrary code execution and denial of service via client-side heap buffer overflow
  • BZ - 2430891 - CVE-2026-23532 freerdp: FreeRDP: Denial of Service and potential code execution via client-side heap buffer overflow

CVEs

  • CVE-2026-23530
  • CVE-2026-23531
  • CVE-2026-23532
  • CVE-2026-23533
  • CVE-2026-23534
  • CVE-2026-23883
  • CVE-2026-23884

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 10

SRPM
freerdp-3.10.3-5.el10_1.1.src.rpm SHA-256: 448183bdad7b703d4661c28100bcec352b836ba38f704adc0f41453db4131075
x86_64
freerdp-3.10.3-5.el10_1.1.x86_64.rpm SHA-256: 68ba316032830a6bf88ee57c917d40a8a009e1ed7922aad4fd8afaca3fb26245
freerdp-debuginfo-3.10.3-5.el10_1.1.x86_64.rpm SHA-256: 3f3efa6b90201f8b02584f53033564ed657a590eabca3209c3fdfb4c364ce4f6
freerdp-debugsource-3.10.3-5.el10_1.1.x86_64.rpm SHA-256: 29e4c30998a8818fb41a0b63375867ed3f7e41742b8eac6526cfe1fc303fb2dc
freerdp-libs-3.10.3-5.el10_1.1.x86_64.rpm SHA-256: 81b470f2cd3d92bb01434b2ae446f6bb80e076cb4891ec00151c3976774981b7
freerdp-libs-debuginfo-3.10.3-5.el10_1.1.x86_64.rpm SHA-256: 3b57f32e06cf1411d8ea377975f244fa5f8c05e168c36ff8e12e86df6990649b
freerdp-server-debuginfo-3.10.3-5.el10_1.1.x86_64.rpm SHA-256: e52ab0e878f70b8a5f2445d71f6f64d4cfddcf36d52e6ec462285b9e6018cc24
libwinpr-3.10.3-5.el10_1.1.x86_64.rpm SHA-256: 274571d9f95b15a51d5c751cc4bda5c3fd08355d6cbafb9256ce8019b3019563
libwinpr-debuginfo-3.10.3-5.el10_1.1.x86_64.rpm SHA-256: 2c7f97552d9182b53b8d43d91543bd9c827407e68627ca87c6f8face3d92423b

Red Hat Enterprise Linux for IBM z Systems 10

SRPM
freerdp-3.10.3-5.el10_1.1.src.rpm SHA-256: 448183bdad7b703d4661c28100bcec352b836ba38f704adc0f41453db4131075
s390x
freerdp-3.10.3-5.el10_1.1.s390x.rpm SHA-256: 2b1c6e1b537d053345872adef893d3344c34c5d445abffec5f1693830f82c6d7
freerdp-debuginfo-3.10.3-5.el10_1.1.s390x.rpm SHA-256: c57e49d3e53030977d56051873fd3e226da85658844d0d415b3d9603deae39e8
freerdp-debugsource-3.10.3-5.el10_1.1.s390x.rpm SHA-256: 966085cdfd8e593fd359b13550fbd75d8daff4acf1bd02014e4e3f93c4069d53
freerdp-libs-3.10.3-5.el10_1.1.s390x.rpm SHA-256: e76e5978417542092abc72daa78b9240e6486b114cc5fe865bb43d545f47aaa3
freerdp-libs-debuginfo-3.10.3-5.el10_1.1.s390x.rpm SHA-256: affd0ce6a6739ea5a04be03ac69d5a7e8eeab270273c3889d221c5ee54f61ec0
freerdp-server-debuginfo-3.10.3-5.el10_1.1.s390x.rpm SHA-256: 6405d06cfb3dde593f1977f759c7af51e52310bd3a75331aa127dc16fa0f92b3
libwinpr-3.10.3-5.el10_1.1.s390x.rpm SHA-256: 07b9ad39401e2df6095144f03bcce5e611773acba9dac9d7b18b85ad569c3a02
libwinpr-debuginfo-3.10.3-5.el10_1.1.s390x.rpm SHA-256: ebe88dc99e32ef8fda61308733ebae68a793cbc00d60987afcb484dc8783db7b

Red Hat Enterprise Linux for Power, little endian 10

SRPM
freerdp-3.10.3-5.el10_1.1.src.rpm SHA-256: 448183bdad7b703d4661c28100bcec352b836ba38f704adc0f41453db4131075
ppc64le
freerdp-3.10.3-5.el10_1.1.ppc64le.rpm SHA-256: a13d2578c606d47c4d9f51ef1f7ea8a4b94c8370e466118644429d8539dbb655
freerdp-debuginfo-3.10.3-5.el10_1.1.ppc64le.rpm SHA-256: d173dcde0c88921b3a33a92b0c9ab0969abcf51104a0ef0aa73dc1274ce9970a
freerdp-debugsource-3.10.3-5.el10_1.1.ppc64le.rpm SHA-256: 02b723cb55e14f2ad198552b8cf47a99096598d2f8b485ba6772d5e358d4e03c
freerdp-libs-3.10.3-5.el10_1.1.ppc64le.rpm SHA-256: d5e4d654809ad23f0467a19227cc2019e0b77ae4f2df4234602b13d5e7cc79c9
freerdp-libs-debuginfo-3.10.3-5.el10_1.1.ppc64le.rpm SHA-256: 9bdd40295ab79c5584daa498e93eb4a6f86323420db34c24eba1513e64d2ea6e
freerdp-server-debuginfo-3.10.3-5.el10_1.1.ppc64le.rpm SHA-256: c4d12286b9e5812d8884986f455d8874abf79bef27e9a6fcccb5785109b57819
libwinpr-3.10.3-5.el10_1.1.ppc64le.rpm SHA-256: b3423845c52ef345d29d428b462356ee2fb257648b336a86ccc5e6838258122e
libwinpr-debuginfo-3.10.3-5.el10_1.1.ppc64le.rpm SHA-256: 86f9927ddee45ba1e59670f3c33926de13da46f461759c3172a662b750ba1378

Red Hat Enterprise Linux for ARM 64 10

SRPM
freerdp-3.10.3-5.el10_1.1.src.rpm SHA-256: 448183bdad7b703d4661c28100bcec352b836ba38f704adc0f41453db4131075
aarch64
freerdp-3.10.3-5.el10_1.1.aarch64.rpm SHA-256: c819ddb50577c8212a7e7ad45bb06fe7deb144938052ca68dba3b9004b5e9c70
freerdp-debuginfo-3.10.3-5.el10_1.1.aarch64.rpm SHA-256: bfdcec991cef2650c93c042b01d530410a09d4ac1dad247b55e18bd946b9e333
freerdp-debugsource-3.10.3-5.el10_1.1.aarch64.rpm SHA-256: 7f764a022ec2f1e7d51d76ba1be3eebde498b4c22d14eff9d7b18dffa6f780d8
freerdp-libs-3.10.3-5.el10_1.1.aarch64.rpm SHA-256: 88438b39b8126998cd88e6233b2076ef012429a1a8ad8a01a6fe827006bb1e18
freerdp-libs-debuginfo-3.10.3-5.el10_1.1.aarch64.rpm SHA-256: 953cf896cba03773c0ea3d3fbac58b711c29760e7c90b9ad0a68bd49dbd5a0dc
freerdp-server-debuginfo-3.10.3-5.el10_1.1.aarch64.rpm SHA-256: 414ef4640303b8f8213e63d04577af16b88d07f90db9e5b0c69a21e4ef98fbef
libwinpr-3.10.3-5.el10_1.1.aarch64.rpm SHA-256: 8c337a519035b29bb7aaa2669886ec44d07a057e98d18e7a0f7cb1732c57f21f
libwinpr-debuginfo-3.10.3-5.el10_1.1.aarch64.rpm SHA-256: 9ae77829a0ed887d214e15cb83fc33e9d7a1454b748f2870caa027246f135f55

Red Hat CodeReady Linux Builder for x86_64 10

SRPM
x86_64
freerdp-debuginfo-3.10.3-5.el10_1.1.x86_64.rpm SHA-256: 3f3efa6b90201f8b02584f53033564ed657a590eabca3209c3fdfb4c364ce4f6
freerdp-debugsource-3.10.3-5.el10_1.1.x86_64.rpm SHA-256: 29e4c30998a8818fb41a0b63375867ed3f7e41742b8eac6526cfe1fc303fb2dc
freerdp-devel-3.10.3-5.el10_1.1.x86_64.rpm SHA-256: cd9633ddf3f6ae69dca227acfc2f738f6e8c0037fcb25f34ba836e80c850ce8e
freerdp-libs-debuginfo-3.10.3-5.el10_1.1.x86_64.rpm SHA-256: 3b57f32e06cf1411d8ea377975f244fa5f8c05e168c36ff8e12e86df6990649b
freerdp-server-3.10.3-5.el10_1.1.x86_64.rpm SHA-256: aa550df39f4e2bb7daa50b249d4b9d11a8e6dfda29a0106f40a2bc2f6c2fd60d
freerdp-server-debuginfo-3.10.3-5.el10_1.1.x86_64.rpm SHA-256: e52ab0e878f70b8a5f2445d71f6f64d4cfddcf36d52e6ec462285b9e6018cc24
libwinpr-debuginfo-3.10.3-5.el10_1.1.x86_64.rpm SHA-256: 2c7f97552d9182b53b8d43d91543bd9c827407e68627ca87c6f8face3d92423b
libwinpr-devel-3.10.3-5.el10_1.1.x86_64.rpm SHA-256: 1852c366aa715174d0fe63b42cf304ffbb8cd430c94fccce39c47ebdc65f582c

Red Hat CodeReady Linux Builder for Power, little endian 10

SRPM
ppc64le
freerdp-debuginfo-3.10.3-5.el10_1.1.ppc64le.rpm SHA-256: d173dcde0c88921b3a33a92b0c9ab0969abcf51104a0ef0aa73dc1274ce9970a
freerdp-debugsource-3.10.3-5.el10_1.1.ppc64le.rpm SHA-256: 02b723cb55e14f2ad198552b8cf47a99096598d2f8b485ba6772d5e358d4e03c
freerdp-devel-3.10.3-5.el10_1.1.ppc64le.rpm SHA-256: fd334abcbb002c9ecc211883f332a3e3636162b4526d2063dcdb7732a8f8104d
freerdp-libs-debuginfo-3.10.3-5.el10_1.1.ppc64le.rpm SHA-256: 9bdd40295ab79c5584daa498e93eb4a6f86323420db34c24eba1513e64d2ea6e
freerdp-server-3.10.3-5.el10_1.1.ppc64le.rpm SHA-256: 65ca72e6aec5aa2087ba1331b26b6df74a651db948c882a15eca98745fc0f715
freerdp-server-debuginfo-3.10.3-5.el10_1.1.ppc64le.rpm SHA-256: c4d12286b9e5812d8884986f455d8874abf79bef27e9a6fcccb5785109b57819
libwinpr-debuginfo-3.10.3-5.el10_1.1.ppc64le.rpm SHA-256: 86f9927ddee45ba1e59670f3c33926de13da46f461759c3172a662b750ba1378
libwinpr-devel-3.10.3-5.el10_1.1.ppc64le.rpm SHA-256: 6456a8d717881d5f420d75b6d4844d39db88fb4fe4df96462a15d63154c83bf4

Red Hat CodeReady Linux Builder for ARM 64 10

SRPM
aarch64
freerdp-debuginfo-3.10.3-5.el10_1.1.aarch64.rpm SHA-256: bfdcec991cef2650c93c042b01d530410a09d4ac1dad247b55e18bd946b9e333
freerdp-debugsource-3.10.3-5.el10_1.1.aarch64.rpm SHA-256: 7f764a022ec2f1e7d51d76ba1be3eebde498b4c22d14eff9d7b18dffa6f780d8
freerdp-devel-3.10.3-5.el10_1.1.aarch64.rpm SHA-256: 6da405b6b8a12af28d9df2976d8adcdc91c54ce0a19fc36e37eea2d978f3970b
freerdp-libs-debuginfo-3.10.3-5.el10_1.1.aarch64.rpm SHA-256: 953cf896cba03773c0ea3d3fbac58b711c29760e7c90b9ad0a68bd49dbd5a0dc
freerdp-server-3.10.3-5.el10_1.1.aarch64.rpm SHA-256: 26051a7f00c326f8d1fb493df8f341f6778873f4dc8b1f84da9c490ca579bcbd
freerdp-server-debuginfo-3.10.3-5.el10_1.1.aarch64.rpm SHA-256: 414ef4640303b8f8213e63d04577af16b88d07f90db9e5b0c69a21e4ef98fbef
libwinpr-debuginfo-3.10.3-5.el10_1.1.aarch64.rpm SHA-256: 9ae77829a0ed887d214e15cb83fc33e9d7a1454b748f2870caa027246f135f55
libwinpr-devel-3.10.3-5.el10_1.1.aarch64.rpm SHA-256: 7b48ebf27d3c770e23d8bb86afb68a4133482589ba7ac2c5aa76cf62e3416a76

Red Hat CodeReady Linux Builder for IBM z Systems 10

SRPM
s390x
freerdp-debuginfo-3.10.3-5.el10_1.1.s390x.rpm SHA-256: c57e49d3e53030977d56051873fd3e226da85658844d0d415b3d9603deae39e8
freerdp-debugsource-3.10.3-5.el10_1.1.s390x.rpm SHA-256: 966085cdfd8e593fd359b13550fbd75d8daff4acf1bd02014e4e3f93c4069d53
freerdp-devel-3.10.3-5.el10_1.1.s390x.rpm SHA-256: 1e9617d8f60238939b30cdd446dca94ef48a9ed30c0bc6de85f105228a54d96b
freerdp-libs-debuginfo-3.10.3-5.el10_1.1.s390x.rpm SHA-256: affd0ce6a6739ea5a04be03ac69d5a7e8eeab270273c3889d221c5ee54f61ec0
freerdp-server-3.10.3-5.el10_1.1.s390x.rpm SHA-256: bdf5109c498b9849f59532e8aefe2d752bcef2d327ac872e04824c234f80b57d
freerdp-server-debuginfo-3.10.3-5.el10_1.1.s390x.rpm SHA-256: 6405d06cfb3dde593f1977f759c7af51e52310bd3a75331aa127dc16fa0f92b3
libwinpr-debuginfo-3.10.3-5.el10_1.1.s390x.rpm SHA-256: ebe88dc99e32ef8fda61308733ebae68a793cbc00d60987afcb484dc8783db7b
libwinpr-devel-3.10.3-5.el10_1.1.s390x.rpm SHA-256: 7c54c268ba44bf7207cd9d567e599674fb864706895fba9098d6a39e73f3d197

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility