Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:60173 - Security Advisory
Issued:
2026-08-26
Updated:
2026-08-26

RHSA-2026:60173 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: freerdp security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for freerdp is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.

Security Fix(es):

  • FreeRDP: FreeRDP: Arbitrary code execution via malicious RDP files (CVE-2026-64624)
  • FreeRDP: FreeRDP: Denial of Service via crafted WindowIcon async message (CVE-2026-67299)
  • FreeRDP: FreeRDP: HTTP Proxy Request Injection via Redirection (CVE-2026-67289)
  • FreeRDP: FreeRDP: Remote code execution or denial of service via audio input integer overflow (CVE-2026-68580)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.4 x86_64
  • Red Hat Enterprise Linux Server - AUS 8.4 x86_64

Fixes

  • BZ - 2503096 - CVE-2026-64624 FreeRDP: FreeRDP: Arbitrary code execution via malicious RDP files
  • BZ - 2509985 - CVE-2026-67299 FreeRDP: FreeRDP: Denial of Service via crafted WindowIcon async message
  • BZ - 2510004 - CVE-2026-67289 FreeRDP: FreeRDP: HTTP Proxy Request Injection via Redirection
  • BZ - 2510125 - CVE-2026-68580 FreeRDP: FreeRDP: Remote code execution or denial of service via audio input integer overflow

CVEs

  • CVE-2026-64624
  • CVE-2026-67289
  • CVE-2026-67299
  • CVE-2026-68580

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.4

SRPM
freerdp-2.2.0-14.el8_4.2.src.rpm SHA-256: f3efe1c2a1e92e68d36a6c671fcf482ad81ab4fd4dfa5716c8b94b69640be5cf
x86_64
freerdp-2.2.0-14.el8_4.2.x86_64.rpm SHA-256: 5174ca5f90a1759fc78851b088b46c0ca9e52c918b74540f44c75a8b9025fee7
freerdp-debuginfo-2.2.0-14.el8_4.2.i686.rpm SHA-256: 3f1ffa28cebade68562b93675abc847b1e0b485579b6e2af8f8fc7c50bc51a61
freerdp-debuginfo-2.2.0-14.el8_4.2.x86_64.rpm SHA-256: edb680103233ceb152d3abba4e9e6182d0a552682352d550712d86b8ea7f5de0
freerdp-debugsource-2.2.0-14.el8_4.2.i686.rpm SHA-256: 4a76a84caca779b94e7db9b0c6b7d0889846fea6e9c26f2aa6291b4dff047389
freerdp-debugsource-2.2.0-14.el8_4.2.x86_64.rpm SHA-256: 37e2ce23119793b266cfc603b4c09bee05235916752c4052e2060c64227a8817
freerdp-libs-2.2.0-14.el8_4.2.i686.rpm SHA-256: f0d5b5bec0eaddfe51f5043ae70b23c7d886e47578b7d6986c97f95ea387bbff
freerdp-libs-2.2.0-14.el8_4.2.x86_64.rpm SHA-256: e179a4ccc8782672350e7a67f284f11aa6472e9a09ed3f4dc5c30d8ef6e29706
freerdp-libs-debuginfo-2.2.0-14.el8_4.2.i686.rpm SHA-256: 38e33f079ad0e7779ff5713615382b1d7be0fe8f6d6ad360d1ea354d52c24d44
freerdp-libs-debuginfo-2.2.0-14.el8_4.2.x86_64.rpm SHA-256: 709eb34773e837bd835be178d77346c9f4b8518006da725328df32bfd699e7e6
libwinpr-2.2.0-14.el8_4.2.i686.rpm SHA-256: 369570f37959f60cbd404e5b2055fba0415bb39bf4095228b527cefc4c4072c5
libwinpr-2.2.0-14.el8_4.2.x86_64.rpm SHA-256: 1c637158a0a40f2480bbee2e807216f119ddce62bab3ba6f2545149cbea54755
libwinpr-debuginfo-2.2.0-14.el8_4.2.i686.rpm SHA-256: a80fb33afdb215b951b56aac0e1414bff24fa449969ead9686c8ff3d00c5661f
libwinpr-debuginfo-2.2.0-14.el8_4.2.x86_64.rpm SHA-256: d2b88f8f787e24a70d4e681e71d9ac3c0ffbf6859acac9d56a603e1cff0b5579
libwinpr-devel-2.2.0-14.el8_4.2.i686.rpm SHA-256: 4733a0bc32f7286bd5ca2c701493008b501a186123cef0010f51ec946bc591e5
libwinpr-devel-2.2.0-14.el8_4.2.x86_64.rpm SHA-256: 68ff41fe7608eb85b32c1fd66eb2ebb14352c1a28ac867a0e9c2f9fb77211783

Red Hat Enterprise Linux Server - AUS 8.4

SRPM
freerdp-2.2.0-14.el8_4.2.src.rpm SHA-256: f3efe1c2a1e92e68d36a6c671fcf482ad81ab4fd4dfa5716c8b94b69640be5cf
x86_64
freerdp-2.2.0-14.el8_4.2.x86_64.rpm SHA-256: 5174ca5f90a1759fc78851b088b46c0ca9e52c918b74540f44c75a8b9025fee7
freerdp-debuginfo-2.2.0-14.el8_4.2.i686.rpm SHA-256: 3f1ffa28cebade68562b93675abc847b1e0b485579b6e2af8f8fc7c50bc51a61
freerdp-debuginfo-2.2.0-14.el8_4.2.x86_64.rpm SHA-256: edb680103233ceb152d3abba4e9e6182d0a552682352d550712d86b8ea7f5de0
freerdp-debugsource-2.2.0-14.el8_4.2.i686.rpm SHA-256: 4a76a84caca779b94e7db9b0c6b7d0889846fea6e9c26f2aa6291b4dff047389
freerdp-debugsource-2.2.0-14.el8_4.2.x86_64.rpm SHA-256: 37e2ce23119793b266cfc603b4c09bee05235916752c4052e2060c64227a8817
freerdp-libs-2.2.0-14.el8_4.2.i686.rpm SHA-256: f0d5b5bec0eaddfe51f5043ae70b23c7d886e47578b7d6986c97f95ea387bbff
freerdp-libs-2.2.0-14.el8_4.2.x86_64.rpm SHA-256: e179a4ccc8782672350e7a67f284f11aa6472e9a09ed3f4dc5c30d8ef6e29706
freerdp-libs-debuginfo-2.2.0-14.el8_4.2.i686.rpm SHA-256: 38e33f079ad0e7779ff5713615382b1d7be0fe8f6d6ad360d1ea354d52c24d44
freerdp-libs-debuginfo-2.2.0-14.el8_4.2.x86_64.rpm SHA-256: 709eb34773e837bd835be178d77346c9f4b8518006da725328df32bfd699e7e6
libwinpr-2.2.0-14.el8_4.2.i686.rpm SHA-256: 369570f37959f60cbd404e5b2055fba0415bb39bf4095228b527cefc4c4072c5
libwinpr-2.2.0-14.el8_4.2.x86_64.rpm SHA-256: 1c637158a0a40f2480bbee2e807216f119ddce62bab3ba6f2545149cbea54755
libwinpr-debuginfo-2.2.0-14.el8_4.2.i686.rpm SHA-256: a80fb33afdb215b951b56aac0e1414bff24fa449969ead9686c8ff3d00c5661f
libwinpr-debuginfo-2.2.0-14.el8_4.2.x86_64.rpm SHA-256: d2b88f8f787e24a70d4e681e71d9ac3c0ffbf6859acac9d56a603e1cff0b5579
libwinpr-devel-2.2.0-14.el8_4.2.i686.rpm SHA-256: 4733a0bc32f7286bd5ca2c701493008b501a186123cef0010f51ec946bc591e5
libwinpr-devel-2.2.0-14.el8_4.2.x86_64.rpm SHA-256: 68ff41fe7608eb85b32c1fd66eb2ebb14352c1a28ac867a0e9c2f9fb77211783

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility