Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:2770 - Security Advisory
Issued:
2026-02-17
Updated:
2026-02-17

RHSA-2026:2770 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: freerdp security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for freerdp is now available for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.

Security Fix(es):

  • freerdp: FreeRDP: Heap buffer overflow leading to denial of service and potential code execution from a malicious server. (CVE-2026-23530)
  • freerdp: FreeRDP: Denial of Service and potential code execution via use-after-free vulnerability (CVE-2026-23884)
  • freerdp: FreeRDP: Arbitrary code execution and denial of service via malicious server (CVE-2026-23883)
  • freerdp: FreeRDP: Heap buffer overflow leads to denial of service and potential code execution (CVE-2026-23533)
  • freerdp: FreeRDP: Heap buffer overflow via crafted RDPGFX surface updates leads to denial of service and potential code execution. (CVE-2026-23531)
  • freerdp: FreeRDP: Denial of Service and potential code execution via client-side heap buffer overflow (CVE-2026-23532)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0 s390x

Fixes

  • BZ - 2430877 - CVE-2026-23530 freerdp: FreeRDP: Heap buffer overflow leading to denial of service and potential code execution from a malicious server.
  • BZ - 2430880 - CVE-2026-23884 freerdp: FreeRDP: Denial of Service and potential code execution via use-after-free vulnerability
  • BZ - 2430885 - CVE-2026-23883 freerdp: FreeRDP: Arbitrary code execution and denial of service via malicious server
  • BZ - 2430886 - CVE-2026-23533 freerdp: FreeRDP: Heap buffer overflow leads to denial of service and potential code execution
  • BZ - 2430887 - CVE-2026-23531 freerdp: FreeRDP: Heap buffer overflow via crafted RDPGFX surface updates leads to denial of service and potential code execution.
  • BZ - 2430891 - CVE-2026-23532 freerdp: FreeRDP: Denial of Service and potential code execution via client-side heap buffer overflow

CVEs

  • CVE-2026-23530
  • CVE-2026-23531
  • CVE-2026-23532
  • CVE-2026-23533
  • CVE-2026-23883
  • CVE-2026-23884

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0

SRPM
freerdp-2.4.1-3.el9_0.src.rpm SHA-256: 52facbbe2dcd2e8be6005b8a990fcc4b5bca10d8068fb368a25dc37a650e3615
ppc64le
freerdp-2.4.1-3.el9_0.ppc64le.rpm SHA-256: 67d4cf8c93bbdd682062f6b9859f446a5ffdaa87721360e386cbed70fa64730d
freerdp-debuginfo-2.4.1-3.el9_0.ppc64le.rpm SHA-256: ebd81edac4d55b97ee1baeb9a5e0c819ba069d9dd036ad40a4e9a5966244c534
freerdp-debugsource-2.4.1-3.el9_0.ppc64le.rpm SHA-256: faf883fc63ccede933e8a9ab4616e973ff7e1074e83f05c182f9715eac9952f0
freerdp-libs-2.4.1-3.el9_0.ppc64le.rpm SHA-256: b8cf7a1ebbfd4bf0a4e26b348c6871c1f9b0988a3c5f5b13dd669f1e16658066
freerdp-libs-debuginfo-2.4.1-3.el9_0.ppc64le.rpm SHA-256: 50c4265c6f045f0e66ad50e0c4a9b03bcf715b47a526354cdad07025f4be9ac5
libwinpr-2.4.1-3.el9_0.ppc64le.rpm SHA-256: 62de150788b82a8ce590fe88ac3480226931bb4cd106f52a3852982daf25093e
libwinpr-debuginfo-2.4.1-3.el9_0.ppc64le.rpm SHA-256: b872a12e93a195372fe32cdec6368086294dd6972c6844374dd7366372ef97c2

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0

SRPM
freerdp-2.4.1-3.el9_0.src.rpm SHA-256: 52facbbe2dcd2e8be6005b8a990fcc4b5bca10d8068fb368a25dc37a650e3615
x86_64
freerdp-2.4.1-3.el9_0.x86_64.rpm SHA-256: 7f1a9d174de597ffab6249a1036153a94b82c01f50da6ad18c71b9420348f1b8
freerdp-debuginfo-2.4.1-3.el9_0.i686.rpm SHA-256: 93c3380c8ec3bdbc2ff8c61654ef9214e4f640b80b1dc61a581b3ad506e69fe4
freerdp-debuginfo-2.4.1-3.el9_0.x86_64.rpm SHA-256: 23e658415e1d80f7cd9b89cf7cc274f98c0a1b2d975b2225ea5e3f1b7eba9c7c
freerdp-debugsource-2.4.1-3.el9_0.i686.rpm SHA-256: 487e029bf6ff0d6de22c9d8dbe18ad86e77a1fa1bbcbc14abf35ef7d9211907a
freerdp-debugsource-2.4.1-3.el9_0.x86_64.rpm SHA-256: 86d0484a48a03bb126021e2b1b3a40a3e3d2b95d9e74b24f4913f08f4b7590c5
freerdp-libs-2.4.1-3.el9_0.i686.rpm SHA-256: 19577d025bc4459ef1213ced671218aab1dd88c846e6af9505ea224337695152
freerdp-libs-2.4.1-3.el9_0.x86_64.rpm SHA-256: a5ae91c89396bb1a2b7051f1041b05186fbbcbadfc2140d1050b744419fbeac7
freerdp-libs-debuginfo-2.4.1-3.el9_0.i686.rpm SHA-256: f2e32f0ec16d072e2460051fd3d4af2d94e628c47cc88f31c5c29dec53e6e05b
freerdp-libs-debuginfo-2.4.1-3.el9_0.x86_64.rpm SHA-256: c431f8c11448c4b5ccd155e36d68948a8f9ab38bdf9557a9a97fcf8bfa475b52
libwinpr-2.4.1-3.el9_0.i686.rpm SHA-256: 0511f647f114551cb46573416807233ec5be1b1ac0f0cda930f54bd098442452
libwinpr-2.4.1-3.el9_0.x86_64.rpm SHA-256: e2a9a810ddbecaf57cee6f0c282374b896ef2811bd1b2997b6e253efcd17da0c
libwinpr-debuginfo-2.4.1-3.el9_0.i686.rpm SHA-256: 87b22bcff8bd900a003e7b7ea57e8004b9c18188bec70c9e4a913e8f2d7ea770
libwinpr-debuginfo-2.4.1-3.el9_0.x86_64.rpm SHA-256: 107415877c79b9cbcb3954448ddf15d38f9ed0275ca0549af30a0e226a03b48c

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0

SRPM
freerdp-2.4.1-3.el9_0.src.rpm SHA-256: 52facbbe2dcd2e8be6005b8a990fcc4b5bca10d8068fb368a25dc37a650e3615
aarch64
freerdp-2.4.1-3.el9_0.aarch64.rpm SHA-256: 32109fc0bace3ee3e6b38d6d0b57cc017f9e0a7219cc64db03432c1e868871ec
freerdp-debuginfo-2.4.1-3.el9_0.aarch64.rpm SHA-256: a8a53bc899c7e81c59b05d5a9013c6acc17d7571f8f7378e0f63c5ee9d19c777
freerdp-debugsource-2.4.1-3.el9_0.aarch64.rpm SHA-256: 84aa9ccc8874f8aa4031541746518ccf1895d9dca5875a7fa0573565128e621b
freerdp-libs-2.4.1-3.el9_0.aarch64.rpm SHA-256: 2b7df7359029b5741788c4ec4a025c4ccdaeee9a58260fbbd6b1ebb7cdc16b35
freerdp-libs-debuginfo-2.4.1-3.el9_0.aarch64.rpm SHA-256: 8db533cdc308c3e0869139340a94b76a9071af21f56e06eebdf4a64960e10f04
libwinpr-2.4.1-3.el9_0.aarch64.rpm SHA-256: 3792440a89674a8f2033b911b3beef06cb70551237f4d6acad6f501ca6ab00f3
libwinpr-debuginfo-2.4.1-3.el9_0.aarch64.rpm SHA-256: f21da352cade461397dc4a435415223c4afa7d948446327d6276597ec29a2fab

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0

SRPM
freerdp-2.4.1-3.el9_0.src.rpm SHA-256: 52facbbe2dcd2e8be6005b8a990fcc4b5bca10d8068fb368a25dc37a650e3615
s390x
freerdp-2.4.1-3.el9_0.s390x.rpm SHA-256: 7a1f3fddc55f96b6d943b6d8d7f3e631b84714506421b24226bd1d83741f1b73
freerdp-debuginfo-2.4.1-3.el9_0.s390x.rpm SHA-256: 97720cf9f00ef2e9e2f75d74fd83e4c1bc1b93a1ef109995de16e421bd63dd62
freerdp-debugsource-2.4.1-3.el9_0.s390x.rpm SHA-256: eee036e82f45da6e87343684e37e6c08a1720733af36d5693b81e0870d499f98
freerdp-libs-2.4.1-3.el9_0.s390x.rpm SHA-256: eeb1e6ec95251a55747f814fc09b0b5e03873d16e04952982741f05611f54f32
freerdp-libs-debuginfo-2.4.1-3.el9_0.s390x.rpm SHA-256: cec4e2e73a5038a18b9e21ee781602bb39b7efd7bcb35357fa54256103acb3d1
libwinpr-2.4.1-3.el9_0.s390x.rpm SHA-256: bc8f24c03909137ba4bba0ba0aa724cae3ecb73133355ea1271430fa2f439c26
libwinpr-debuginfo-2.4.1-3.el9_0.s390x.rpm SHA-256: 94cb6fbf4ffd8540500b9ef9126e19a2e9b069ecda5f60b7b813ff3877f24d1e

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility