Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:6004 - Security Advisory
Issued:
2026-03-30
Updated:
2026-03-30

RHSA-2026:6004 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: freerdp security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for freerdp is now available for Red Hat Enterprise Linux 9.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.

Security Fix(es):

  • freerdp: FreeRDP: Arbitrary code execution via heap out-of-bounds write in RLE planar decode path (CVE-2026-26965)
  • freerdp: FreeRDP: Arbitrary code execution via heap buffer overflow in GDI surface pipeline (CVE-2026-26955)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 9 s390x
  • Red Hat Enterprise Linux for Power, little endian 9 ppc64le
  • Red Hat Enterprise Linux for ARM 64 9 aarch64
  • Red Hat CodeReady Linux Builder for x86_64 9 x86_64
  • Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le
  • Red Hat CodeReady Linux Builder for ARM 64 9 aarch64
  • Red Hat CodeReady Linux Builder for IBM z Systems 9 s390x

Fixes

  • BZ - 2442959 - CVE-2026-26965 freerdp: FreeRDP: Arbitrary code execution via heap out-of-bounds write in RLE planar decode path
  • BZ - 2443132 - CVE-2026-26955 freerdp: FreeRDP: Arbitrary code execution via heap buffer overflow in GDI surface pipeline

CVEs

  • CVE-2026-26955
  • CVE-2026-26965

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 9

SRPM
freerdp-2.11.7-1.el9_7.3.src.rpm SHA-256: 03ee5df36b8d8d2a7778eeb85ce7876f65bdf5b7ef66e8dee96c21adb75e35e9
x86_64
freerdp-2.11.7-1.el9_7.3.x86_64.rpm SHA-256: e2207fd1df60303a2f20ae454e136f84c629970af513fa47044dd9be6daa620b
freerdp-debuginfo-2.11.7-1.el9_7.3.i686.rpm SHA-256: 3980025fa1573c9772550a0d0abf91f91db12fb163f066399055a0a81e2d9f60
freerdp-debuginfo-2.11.7-1.el9_7.3.x86_64.rpm SHA-256: 529c5a4f12e4926b2ce7815042bf2bb4c7af71701bc6839b8a3da569564d4870
freerdp-debugsource-2.11.7-1.el9_7.3.i686.rpm SHA-256: 1f3246a2688f0aa9402048b5bf5cbbb3cbde8bd741a398f0360554fee0c4b7ce
freerdp-debugsource-2.11.7-1.el9_7.3.x86_64.rpm SHA-256: a74feae9fe2b7b96ced36921d07b568106052ad7726f8746599e8a75a27b6271
freerdp-libs-2.11.7-1.el9_7.3.i686.rpm SHA-256: 5c51c124acafe35863907ed1e614ecc501f872a5481a080c6cad39a1c4b1c131
freerdp-libs-2.11.7-1.el9_7.3.x86_64.rpm SHA-256: 1c7fa42033317b43a6f7dab21f2874ec48fefce3b158607cb9e55b1b21625dc5
freerdp-libs-debuginfo-2.11.7-1.el9_7.3.i686.rpm SHA-256: 5b47d9b64a06932752b327789187395c98c6debb4378e4a76efe0274a4314632
freerdp-libs-debuginfo-2.11.7-1.el9_7.3.x86_64.rpm SHA-256: 083a51abb758e08ceb8ad33b211bd83602039c84313ab11bf18039652978a090
libwinpr-2.11.7-1.el9_7.3.i686.rpm SHA-256: 75778b21d70ceb2be89278b563c5ad24443a3d43476f963ace1b6bff7cb1cee8
libwinpr-2.11.7-1.el9_7.3.x86_64.rpm SHA-256: 6acff7911a2a8b444d80c86b82d4ea648ae3dad34267356299e30f4dc45118f7
libwinpr-debuginfo-2.11.7-1.el9_7.3.i686.rpm SHA-256: 0a820adfb8df181fcbd1d1708733d16ee25a3648fa2f039836fc085c9d29d211
libwinpr-debuginfo-2.11.7-1.el9_7.3.x86_64.rpm SHA-256: dbc64fd4e41674831edd3f6b073a6e5e0b8492399de9e378f7e45c25b6c2dcd5

Red Hat Enterprise Linux for IBM z Systems 9

SRPM
freerdp-2.11.7-1.el9_7.3.src.rpm SHA-256: 03ee5df36b8d8d2a7778eeb85ce7876f65bdf5b7ef66e8dee96c21adb75e35e9
s390x
freerdp-2.11.7-1.el9_7.3.s390x.rpm SHA-256: b4f712880f411bb60623532f0d4956e291676aa541a27dde309fddfbe4cfe352
freerdp-debuginfo-2.11.7-1.el9_7.3.s390x.rpm SHA-256: 54cf5a4f700c0d3815384090f84a84cd271dbcc81b6ea764efba6069e0331d1d
freerdp-debugsource-2.11.7-1.el9_7.3.s390x.rpm SHA-256: de7a26d983a4ba23b4af443be2cc6584a5e300d88fdaa78d27111cab438e350c
freerdp-libs-2.11.7-1.el9_7.3.s390x.rpm SHA-256: 93f60c527c56c78fee1a738fb3564d4c0cb61d6a1e93aedefb36522c51b05354
freerdp-libs-debuginfo-2.11.7-1.el9_7.3.s390x.rpm SHA-256: 17bfd6096e38ce896d4b65478faf58e15a172eb36f4df9f55cec6f406312e320
libwinpr-2.11.7-1.el9_7.3.s390x.rpm SHA-256: a1b8aadb8df17b34f62858553d3bd262aa4cd04485d87ccf23b47eb059c7a3fe
libwinpr-debuginfo-2.11.7-1.el9_7.3.s390x.rpm SHA-256: 6b462930c49987276d9c339aceaaa896c68db2e9ffd938eec3f40cec3e84057f

Red Hat Enterprise Linux for Power, little endian 9

SRPM
freerdp-2.11.7-1.el9_7.3.src.rpm SHA-256: 03ee5df36b8d8d2a7778eeb85ce7876f65bdf5b7ef66e8dee96c21adb75e35e9
ppc64le
freerdp-2.11.7-1.el9_7.3.ppc64le.rpm SHA-256: 5c0d7292c5fc52738f3cd52a0feb23ec5967968f06b23946861cd4b262176d73
freerdp-debuginfo-2.11.7-1.el9_7.3.ppc64le.rpm SHA-256: 6585cf8586331ac276494a06ab28119aae5c67304684a076838bc48f7cdcf76b
freerdp-debugsource-2.11.7-1.el9_7.3.ppc64le.rpm SHA-256: 66b950f3b24eab67d55370934c704b1c6207a2da6c325500cc06383cf4b1779a
freerdp-libs-2.11.7-1.el9_7.3.ppc64le.rpm SHA-256: 239034e986838a4c2458d93c314df48681deaff91aab8fa525e30ac6c7ed2a52
freerdp-libs-debuginfo-2.11.7-1.el9_7.3.ppc64le.rpm SHA-256: 725338372e0eb052e7d0c4b1f5e482a4f698558d52260a04c7d02622b7437cf7
libwinpr-2.11.7-1.el9_7.3.ppc64le.rpm SHA-256: 808489305fb09b148395bc3f63a36f58708c1819da545ac4a9b28a96e91ad049
libwinpr-debuginfo-2.11.7-1.el9_7.3.ppc64le.rpm SHA-256: 7fc8b65ee26b28af7f3642dc397534b6caed90c7badbd23c0a7dd13a98648f46

Red Hat Enterprise Linux for ARM 64 9

SRPM
freerdp-2.11.7-1.el9_7.3.src.rpm SHA-256: 03ee5df36b8d8d2a7778eeb85ce7876f65bdf5b7ef66e8dee96c21adb75e35e9
aarch64
freerdp-2.11.7-1.el9_7.3.aarch64.rpm SHA-256: 85d9b56250805f54f2dfec416f7dc022d93e32f9aec2d4ee313e9f94a660dd70
freerdp-debuginfo-2.11.7-1.el9_7.3.aarch64.rpm SHA-256: f5e332da11d8fd3217ce4f371792371977e7647f043e6f4eb40b9107cb460815
freerdp-debugsource-2.11.7-1.el9_7.3.aarch64.rpm SHA-256: b38994ba79b1600d4cfe56a8a9dab93d50c12c5c83a69546efeedf63869e2d9b
freerdp-libs-2.11.7-1.el9_7.3.aarch64.rpm SHA-256: 28153f55193138f8972e94768b3e0196e7256103237f1fd634c331a5ddd1db4b
freerdp-libs-debuginfo-2.11.7-1.el9_7.3.aarch64.rpm SHA-256: bd3535b89fe6bca3a2c73b2aba58e554d884438e56caf238b9ddd8de946d9bc3
libwinpr-2.11.7-1.el9_7.3.aarch64.rpm SHA-256: c8c14603c47433c80b42bc267d84e3e6bd3b6d77ea89fe3bec0d8349fd2d9791
libwinpr-debuginfo-2.11.7-1.el9_7.3.aarch64.rpm SHA-256: 1acbfc6575d0b06cbc3506524f50d2e2b7230a3ef54b857bde2a3bc03d416534

Red Hat CodeReady Linux Builder for x86_64 9

SRPM
x86_64
freerdp-debuginfo-2.11.7-1.el9_7.3.i686.rpm SHA-256: 3980025fa1573c9772550a0d0abf91f91db12fb163f066399055a0a81e2d9f60
freerdp-debuginfo-2.11.7-1.el9_7.3.x86_64.rpm SHA-256: 529c5a4f12e4926b2ce7815042bf2bb4c7af71701bc6839b8a3da569564d4870
freerdp-debugsource-2.11.7-1.el9_7.3.i686.rpm SHA-256: 1f3246a2688f0aa9402048b5bf5cbbb3cbde8bd741a398f0360554fee0c4b7ce
freerdp-debugsource-2.11.7-1.el9_7.3.x86_64.rpm SHA-256: a74feae9fe2b7b96ced36921d07b568106052ad7726f8746599e8a75a27b6271
freerdp-devel-2.11.7-1.el9_7.3.i686.rpm SHA-256: 451dbdc7e14f37d7885da5f568cb8ff0dcaed83392a4d31f47430fc96760f849
freerdp-devel-2.11.7-1.el9_7.3.x86_64.rpm SHA-256: 66e396b82dcac3f7696bd772e7d3d2e4bcc7046b55159c04f4f34b7c1c694bc6
freerdp-libs-debuginfo-2.11.7-1.el9_7.3.i686.rpm SHA-256: 5b47d9b64a06932752b327789187395c98c6debb4378e4a76efe0274a4314632
freerdp-libs-debuginfo-2.11.7-1.el9_7.3.x86_64.rpm SHA-256: 083a51abb758e08ceb8ad33b211bd83602039c84313ab11bf18039652978a090
libwinpr-debuginfo-2.11.7-1.el9_7.3.i686.rpm SHA-256: 0a820adfb8df181fcbd1d1708733d16ee25a3648fa2f039836fc085c9d29d211
libwinpr-debuginfo-2.11.7-1.el9_7.3.x86_64.rpm SHA-256: dbc64fd4e41674831edd3f6b073a6e5e0b8492399de9e378f7e45c25b6c2dcd5
libwinpr-devel-2.11.7-1.el9_7.3.i686.rpm SHA-256: 8e129e16a7c4d44612461bdd9faa727f795d5a01a93285ac3e6febef3a8ecb0a
libwinpr-devel-2.11.7-1.el9_7.3.x86_64.rpm SHA-256: 6259c5f046241fa3b5c02d184fa2de2d247384b698707952e15c31a4f60aa299

Red Hat CodeReady Linux Builder for Power, little endian 9

SRPM
ppc64le
freerdp-debuginfo-2.11.7-1.el9_7.3.ppc64le.rpm SHA-256: 6585cf8586331ac276494a06ab28119aae5c67304684a076838bc48f7cdcf76b
freerdp-debugsource-2.11.7-1.el9_7.3.ppc64le.rpm SHA-256: 66b950f3b24eab67d55370934c704b1c6207a2da6c325500cc06383cf4b1779a
freerdp-devel-2.11.7-1.el9_7.3.ppc64le.rpm SHA-256: 65359fb52e925c447b2d93330974e67996fe11129bd52059378234227a387e7f
freerdp-libs-debuginfo-2.11.7-1.el9_7.3.ppc64le.rpm SHA-256: 725338372e0eb052e7d0c4b1f5e482a4f698558d52260a04c7d02622b7437cf7
libwinpr-debuginfo-2.11.7-1.el9_7.3.ppc64le.rpm SHA-256: 7fc8b65ee26b28af7f3642dc397534b6caed90c7badbd23c0a7dd13a98648f46
libwinpr-devel-2.11.7-1.el9_7.3.ppc64le.rpm SHA-256: 6dd299020e972bfffe89fcb10390c063684b6d3f4672b8b52a57d0fcab3e4c55

Red Hat CodeReady Linux Builder for ARM 64 9

SRPM
aarch64
freerdp-debuginfo-2.11.7-1.el9_7.3.aarch64.rpm SHA-256: f5e332da11d8fd3217ce4f371792371977e7647f043e6f4eb40b9107cb460815
freerdp-debugsource-2.11.7-1.el9_7.3.aarch64.rpm SHA-256: b38994ba79b1600d4cfe56a8a9dab93d50c12c5c83a69546efeedf63869e2d9b
freerdp-devel-2.11.7-1.el9_7.3.aarch64.rpm SHA-256: 8619d7898662500aa25ac7f02ea6e16e12e8757933e9e4865f1b20afab04aef8
freerdp-libs-debuginfo-2.11.7-1.el9_7.3.aarch64.rpm SHA-256: bd3535b89fe6bca3a2c73b2aba58e554d884438e56caf238b9ddd8de946d9bc3
libwinpr-debuginfo-2.11.7-1.el9_7.3.aarch64.rpm SHA-256: 1acbfc6575d0b06cbc3506524f50d2e2b7230a3ef54b857bde2a3bc03d416534
libwinpr-devel-2.11.7-1.el9_7.3.aarch64.rpm SHA-256: 59f0c0004a4e47091dd4e12d70989ab10e35dde1c9ed746db6eaee40f44108e6

Red Hat CodeReady Linux Builder for IBM z Systems 9

SRPM
s390x
freerdp-debuginfo-2.11.7-1.el9_7.3.s390x.rpm SHA-256: 54cf5a4f700c0d3815384090f84a84cd271dbcc81b6ea764efba6069e0331d1d
freerdp-debugsource-2.11.7-1.el9_7.3.s390x.rpm SHA-256: de7a26d983a4ba23b4af443be2cc6584a5e300d88fdaa78d27111cab438e350c
freerdp-devel-2.11.7-1.el9_7.3.s390x.rpm SHA-256: 41abbc257711e9188d6ddf5472e48354f8f6a52b25db0f7d9869d2d728133036
freerdp-libs-debuginfo-2.11.7-1.el9_7.3.s390x.rpm SHA-256: 17bfd6096e38ce896d4b65478faf58e15a172eb36f4df9f55cec6f406312e320
libwinpr-debuginfo-2.11.7-1.el9_7.3.s390x.rpm SHA-256: 6b462930c49987276d9c339aceaaa896c68db2e9ffd938eec3f40cec3e84057f
libwinpr-devel-2.11.7-1.el9_7.3.s390x.rpm SHA-256: 322296c734ff001f8db243c636dd4d3d384774d532d9840e91444f33ffd99f20

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility