Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:3038 - Security Advisory
Issued:
2026-02-23
Updated:
2026-02-23

RHSA-2026:3038 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: freerdp security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for freerdp is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.

Security Fix(es):

  • freerdp: FreeRDP: Heap buffer overflow leading to denial of service and potential code execution from a malicious server. (CVE-2026-23530)
  • freerdp: FreeRDP: Denial of Service and potential code execution via use-after-free vulnerability (CVE-2026-23884)
  • freerdp: FreeRDP: Heap buffer overflow leads to denial of service and potential code execution (CVE-2026-23533)
  • freerdp: FreeRDP: Heap buffer overflow via crafted RDPGFX surface updates leads to denial of service and potential code execution. (CVE-2026-23531)
  • freerdp: FreeRDP: Denial of Service and potential code execution via client-side heap buffer overflow (CVE-2026-23532)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4 x86_64
  • Red Hat Enterprise Linux Server - AUS 8.4 x86_64

Fixes

  • BZ - 2430877 - CVE-2026-23530 freerdp: FreeRDP: Heap buffer overflow leading to denial of service and potential code execution from a malicious server.
  • BZ - 2430880 - CVE-2026-23884 freerdp: FreeRDP: Denial of Service and potential code execution via use-after-free vulnerability
  • BZ - 2430886 - CVE-2026-23533 freerdp: FreeRDP: Heap buffer overflow leads to denial of service and potential code execution
  • BZ - 2430887 - CVE-2026-23531 freerdp: FreeRDP: Heap buffer overflow via crafted RDPGFX surface updates leads to denial of service and potential code execution.
  • BZ - 2430891 - CVE-2026-23532 freerdp: FreeRDP: Denial of Service and potential code execution via client-side heap buffer overflow

CVEs

  • CVE-2026-23530
  • CVE-2026-23531
  • CVE-2026-23532
  • CVE-2026-23533
  • CVE-2026-23884

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4

SRPM
freerdp-2.2.0-7.el8_4.src.rpm SHA-256: 0798ea090fd049d9d3cff60158acdf844bde5268d8e486d8fd8c82738883d1f5
x86_64
freerdp-2.2.0-7.el8_4.x86_64.rpm SHA-256: fba4354773187be6d19bd0090ead63432e574d8c354d84a7e68b9e20b11f3e33
freerdp-debuginfo-2.2.0-7.el8_4.i686.rpm SHA-256: 15494550cc414837f71137e581c865c38f99d94318a19b04353e41c2748d542f
freerdp-debuginfo-2.2.0-7.el8_4.x86_64.rpm SHA-256: 4d77e73dd84c77d0fe3d3a8c70c7dc7cc3113645abfafee8b0efd44d24cf6a42
freerdp-debugsource-2.2.0-7.el8_4.i686.rpm SHA-256: 18eccc1bdbda89aac316be13096d56a4e52e3d5965bdb7c890ed9f1b34c51c74
freerdp-debugsource-2.2.0-7.el8_4.x86_64.rpm SHA-256: 7e1210484287abb6e50897ea7344def7caeb1efab46c0640d120aa231d617dcb
freerdp-libs-2.2.0-7.el8_4.i686.rpm SHA-256: 7272e73a9bd64d46303626cda5f9e3b1b17c93287883bc100b8c7ec46a7d388e
freerdp-libs-2.2.0-7.el8_4.x86_64.rpm SHA-256: bb0292c41909f202f8670b940d218f52e313512a9cb75d67c3077de57b065865
freerdp-libs-debuginfo-2.2.0-7.el8_4.i686.rpm SHA-256: f4ff5a97ebdb07422995412fe56b5b3773c8467d57948ce912706cf8499f111e
freerdp-libs-debuginfo-2.2.0-7.el8_4.x86_64.rpm SHA-256: 95ce8fd63c44575fb601c67204196a221e8fa9067e9dfb870665285fc4e4427c
libwinpr-2.2.0-7.el8_4.i686.rpm SHA-256: d2f5c7e6ec4fa28ad85f50be8d53dbccdc95f04d84d3d399d625a75cd4392697
libwinpr-2.2.0-7.el8_4.x86_64.rpm SHA-256: 7100585f692d5a0795c9c02ee5335a6c4e7eefd02f0dc455b5d7351786245ff4
libwinpr-debuginfo-2.2.0-7.el8_4.i686.rpm SHA-256: 1bf8def1ac1da755069f24187a07a2bc78dcb1a19cfea68a336195c4cdb0d20c
libwinpr-debuginfo-2.2.0-7.el8_4.x86_64.rpm SHA-256: 380f86c48fddbc9d6c77c173f8ca7db293208ebf4f71993e2a9c6482f8989867
libwinpr-devel-2.2.0-7.el8_4.i686.rpm SHA-256: 8b93d823591c79d0ceb81a803cd09434ccaa42af4534d26022c0ce52c7a1f4d2
libwinpr-devel-2.2.0-7.el8_4.x86_64.rpm SHA-256: 81b72f44df6c301401286e7b91e4733fe39873225204c0cc1e7b57fea9b807da

Red Hat Enterprise Linux Server - AUS 8.4

SRPM
freerdp-2.2.0-7.el8_4.src.rpm SHA-256: 0798ea090fd049d9d3cff60158acdf844bde5268d8e486d8fd8c82738883d1f5
x86_64
freerdp-2.2.0-7.el8_4.x86_64.rpm SHA-256: fba4354773187be6d19bd0090ead63432e574d8c354d84a7e68b9e20b11f3e33
freerdp-debuginfo-2.2.0-7.el8_4.i686.rpm SHA-256: 15494550cc414837f71137e581c865c38f99d94318a19b04353e41c2748d542f
freerdp-debuginfo-2.2.0-7.el8_4.x86_64.rpm SHA-256: 4d77e73dd84c77d0fe3d3a8c70c7dc7cc3113645abfafee8b0efd44d24cf6a42
freerdp-debugsource-2.2.0-7.el8_4.i686.rpm SHA-256: 18eccc1bdbda89aac316be13096d56a4e52e3d5965bdb7c890ed9f1b34c51c74
freerdp-debugsource-2.2.0-7.el8_4.x86_64.rpm SHA-256: 7e1210484287abb6e50897ea7344def7caeb1efab46c0640d120aa231d617dcb
freerdp-libs-2.2.0-7.el8_4.i686.rpm SHA-256: 7272e73a9bd64d46303626cda5f9e3b1b17c93287883bc100b8c7ec46a7d388e
freerdp-libs-2.2.0-7.el8_4.x86_64.rpm SHA-256: bb0292c41909f202f8670b940d218f52e313512a9cb75d67c3077de57b065865
freerdp-libs-debuginfo-2.2.0-7.el8_4.i686.rpm SHA-256: f4ff5a97ebdb07422995412fe56b5b3773c8467d57948ce912706cf8499f111e
freerdp-libs-debuginfo-2.2.0-7.el8_4.x86_64.rpm SHA-256: 95ce8fd63c44575fb601c67204196a221e8fa9067e9dfb870665285fc4e4427c
libwinpr-2.2.0-7.el8_4.i686.rpm SHA-256: d2f5c7e6ec4fa28ad85f50be8d53dbccdc95f04d84d3d399d625a75cd4392697
libwinpr-2.2.0-7.el8_4.x86_64.rpm SHA-256: 7100585f692d5a0795c9c02ee5335a6c4e7eefd02f0dc455b5d7351786245ff4
libwinpr-debuginfo-2.2.0-7.el8_4.i686.rpm SHA-256: 1bf8def1ac1da755069f24187a07a2bc78dcb1a19cfea68a336195c4cdb0d20c
libwinpr-debuginfo-2.2.0-7.el8_4.x86_64.rpm SHA-256: 380f86c48fddbc9d6c77c173f8ca7db293208ebf4f71993e2a9c6482f8989867
libwinpr-devel-2.2.0-7.el8_4.i686.rpm SHA-256: 8b93d823591c79d0ceb81a803cd09434ccaa42af4534d26022c0ce52c7a1f4d2
libwinpr-devel-2.2.0-7.el8_4.x86_64.rpm SHA-256: 81b72f44df6c301401286e7b91e4733fe39873225204c0cc1e7b57fea9b807da

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility