Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:6395 - Security Advisory
Issued:
2026-04-01
Updated:
2026-04-01

RHSA-2026:6395 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: freerdp security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for freerdp is now available for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.

Security Fix(es):

  • freerdp: FreeRDP: Arbitrary code execution via heap out-of-bounds write in RLE planar decode path (CVE-2026-26965)
  • freerdp: FreeRDP: Arbitrary code execution via heap buffer overflow in GDI surface pipeline (CVE-2026-26955)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0 s390x

Fixes

  • BZ - 2442959 - CVE-2026-26965 freerdp: FreeRDP: Arbitrary code execution via heap out-of-bounds write in RLE planar decode path
  • BZ - 2443132 - CVE-2026-26955 freerdp: FreeRDP: Arbitrary code execution via heap buffer overflow in GDI surface pipeline

CVEs

  • CVE-2026-26955
  • CVE-2026-26965

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0

SRPM
freerdp-2.4.1-3.el9_0.2.src.rpm SHA-256: c872cd072c86523e8a2fbce4b25f2a3cc94ee1c21800936ccf33c02d2376175d
ppc64le
freerdp-2.4.1-3.el9_0.2.ppc64le.rpm SHA-256: fb3ba1d40ad862f6c52395517764750444919c8de9a59f0a42412a62120f2db1
freerdp-debuginfo-2.4.1-3.el9_0.2.ppc64le.rpm SHA-256: 62f0ec520beec2642652551828c80de1f5755cfa25d9cf57e3f832c51e2db606
freerdp-debugsource-2.4.1-3.el9_0.2.ppc64le.rpm SHA-256: cb2a1b8a47db1e17b29ef87e91d4c8177826ca2435aa03e61534f048510cf911
freerdp-libs-2.4.1-3.el9_0.2.ppc64le.rpm SHA-256: 508dd29c4e1da4e35215daa5c43b5b8c1a028ff2586e791e6bb82cf5170afda5
freerdp-libs-debuginfo-2.4.1-3.el9_0.2.ppc64le.rpm SHA-256: 2940d0f1add47ade5e2c79a20ea5c5c55210e8157183f2f71041e503b259b02b
libwinpr-2.4.1-3.el9_0.2.ppc64le.rpm SHA-256: 4e330eb37511fb29c400a67e8195905a9bc6e8e6a21ade08de9823124baf8c91
libwinpr-debuginfo-2.4.1-3.el9_0.2.ppc64le.rpm SHA-256: 06db82626deb060d42edc6fc314893681c2d0e61f07437b216b8b2eacf83c6b7

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0

SRPM
freerdp-2.4.1-3.el9_0.2.src.rpm SHA-256: c872cd072c86523e8a2fbce4b25f2a3cc94ee1c21800936ccf33c02d2376175d
x86_64
freerdp-2.4.1-3.el9_0.2.x86_64.rpm SHA-256: 556248d8f3181e9d26c514fd5b182b90fd261bdba7b8d88bfea5171ec3a2a734
freerdp-debuginfo-2.4.1-3.el9_0.2.i686.rpm SHA-256: 6ef36bc3a6b81ac1bc400c0c2a92d8fab4eeca6b8700e26519f507e808aa2434
freerdp-debuginfo-2.4.1-3.el9_0.2.x86_64.rpm SHA-256: 4803b335e8f3bd09e5fd53cb86dab4ab13fff1e333b37a59d34726d907164211
freerdp-debugsource-2.4.1-3.el9_0.2.i686.rpm SHA-256: 40a588309194ab45aa7dfb0e8e9fd32e126a1d2533dbcbe10e45f99ea27fee58
freerdp-debugsource-2.4.1-3.el9_0.2.x86_64.rpm SHA-256: e22efb5c346caaeab8923bd640eb132ef068e42b6885715699079b4813f429ff
freerdp-libs-2.4.1-3.el9_0.2.i686.rpm SHA-256: 10e7cb7110fd48ba97ed7b88937004a4c619d7b07864b343bfc337f2fdcb2fc3
freerdp-libs-2.4.1-3.el9_0.2.x86_64.rpm SHA-256: 622fa51108d7d8c8017c75189f4271b4c376530a3dcc3adde94f5ab810f845f8
freerdp-libs-debuginfo-2.4.1-3.el9_0.2.i686.rpm SHA-256: 5a83e9c814250a324ffcea580805abbc73105191505dc0d04c60c64159a767d4
freerdp-libs-debuginfo-2.4.1-3.el9_0.2.x86_64.rpm SHA-256: 05e83cafeebb157992255010d4100e79d76abfc48083cac15044d5d0d228b339
libwinpr-2.4.1-3.el9_0.2.i686.rpm SHA-256: c387cae14423409d1f34e5b8bd488ced7e8e6d3659087be069c9bfa98b200846
libwinpr-2.4.1-3.el9_0.2.x86_64.rpm SHA-256: abab27e38bdb4b161dadb4a80a2280e383b8d290651605e8f53fb47a8f521951
libwinpr-debuginfo-2.4.1-3.el9_0.2.i686.rpm SHA-256: f956e25b34095026a625026adbc22156be02449a41aca59c801879f038483875
libwinpr-debuginfo-2.4.1-3.el9_0.2.x86_64.rpm SHA-256: db11e050eacf62521329f3c6704a06017e8a3c2ee4867ca5f727892a2674d17e

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0

SRPM
freerdp-2.4.1-3.el9_0.2.src.rpm SHA-256: c872cd072c86523e8a2fbce4b25f2a3cc94ee1c21800936ccf33c02d2376175d
aarch64
freerdp-2.4.1-3.el9_0.2.aarch64.rpm SHA-256: 494620c6ea3114210d5c0a41b404e7d29b6da862a89c840bd968d757a8267c6c
freerdp-debuginfo-2.4.1-3.el9_0.2.aarch64.rpm SHA-256: 7ca379d30493e4a98673946e97acc7a8156310b16397161c220766220daaccaa
freerdp-debugsource-2.4.1-3.el9_0.2.aarch64.rpm SHA-256: 096647d61155ca6b7bf079b3e76fd86ab4db4ace92dbca569f88514d20f95dbb
freerdp-libs-2.4.1-3.el9_0.2.aarch64.rpm SHA-256: 36715d35735f9e5c596758006e1f0ba151bb1fdb55af9035ded2932b02c3d2db
freerdp-libs-debuginfo-2.4.1-3.el9_0.2.aarch64.rpm SHA-256: 29a226bc9847aa873c39e2b2a7bbd4153c4af0c9c99efeb29ea974111a2725c2
libwinpr-2.4.1-3.el9_0.2.aarch64.rpm SHA-256: 4ced2efadaf3bf8c7da7744345f09178271349bba534d5b3d80bd3ba2de0e2ca
libwinpr-debuginfo-2.4.1-3.el9_0.2.aarch64.rpm SHA-256: 72c5bee94e22a737494813eebe16a37f69e352bc90a0b73a4d65c9bccd9368a8

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0

SRPM
freerdp-2.4.1-3.el9_0.2.src.rpm SHA-256: c872cd072c86523e8a2fbce4b25f2a3cc94ee1c21800936ccf33c02d2376175d
s390x
freerdp-2.4.1-3.el9_0.2.s390x.rpm SHA-256: 735d8a6add82e90634135665683d6afd1a06155af6734cedae0b8edfc672657d
freerdp-debuginfo-2.4.1-3.el9_0.2.s390x.rpm SHA-256: 2735caba3970ab0a28ef8382f6ba7a8f8abf894f3e648630656f424c8e4b8e48
freerdp-debugsource-2.4.1-3.el9_0.2.s390x.rpm SHA-256: 570a294d329c734fdab15d36b1e48c5000859471a55e15527939aa8822dc5163
freerdp-libs-2.4.1-3.el9_0.2.s390x.rpm SHA-256: 50abb2dc41878dc76b2518b598cd0789cc0cc58f92038b881b1d69dd2436f8f2
freerdp-libs-debuginfo-2.4.1-3.el9_0.2.s390x.rpm SHA-256: d192e5f637ebed5be3ce66ef3736e5c93eee3ac798069dd55e1b64c55bdc2559
libwinpr-2.4.1-3.el9_0.2.s390x.rpm SHA-256: b040181f09e2a251a335b521167180a57773ce8506c61a57788c2d6fb4d2b570
libwinpr-debuginfo-2.4.1-3.el9_0.2.s390x.rpm SHA-256: f5d9c9ecc216f0af19116d0b88f765c7144ccb47834244b82edbcd68f1f937e6

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility