Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:65855 - Security Advisory
Issued:
2026-09-09
Updated:
2026-09-09

RHSA-2026:65855 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: freerdp security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for freerdp is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.

Security Fix(es):

  • FreeRDP: FreeRDP: Memory disclosure or denial of service via crafted RDP update orders (CVE-2026-67301)
  • FreeRDP: FreeRDP: Denial of Service via crafted smartcard cache requests (CVE-2026-67288)
  • FreeRDP: FreeRDP: Denial of Service via heap out-of-bounds read (CVE-2026-67291)
  • FreeRDP: FreeRDP: Heap-buffer-overflow allows arbitrary code execution via crafted RPC response (CVE-2026-55194)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.4 x86_64
  • Red Hat Enterprise Linux Server - AUS 8.4 x86_64

Fixes

  • BZ - 2509994 - CVE-2026-67301 FreeRDP: FreeRDP: Memory disclosure or denial of service via crafted RDP update orders
  • BZ - 2510001 - CVE-2026-67288 FreeRDP: FreeRDP: Denial of Service via crafted smartcard cache requests
  • BZ - 2510010 - CVE-2026-67291 FreeRDP: FreeRDP: Denial of Service via heap out-of-bounds read
  • BZ - 2519824 - CVE-2026-55194 FreeRDP: FreeRDP: Heap-buffer-overflow allows arbitrary code execution via crafted RPC response

CVEs

  • CVE-2026-55194
  • CVE-2026-67288
  • CVE-2026-67291
  • CVE-2026-67301

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.4

SRPM
freerdp-2.2.0-14.el8_4.3.src.rpm SHA-256: cea7c9b1e36196228a23074e6e724b9d0706178eb9ae8e7b114b9a8aeb7d2913
x86_64
freerdp-2.2.0-14.el8_4.3.x86_64.rpm SHA-256: 5bbd1c0b5a55daecfad8a81eba5518b20ff34a8c80a5f53446cc434b879da69f
freerdp-debuginfo-2.2.0-14.el8_4.3.i686.rpm SHA-256: 7c9ae97f6958dfce4665f1163c5760e78b2d7bffb8f67da1804e7ca1c4f7d918
freerdp-debuginfo-2.2.0-14.el8_4.3.x86_64.rpm SHA-256: 89dec8b3231000eae3654ec3e19555b0b271b73601629222b3e05801591ce706
freerdp-debugsource-2.2.0-14.el8_4.3.i686.rpm SHA-256: 12630599c1839d7d7d3f4d98c3bc6370966ff3a2c48ee529b1f77a7654a2ade0
freerdp-debugsource-2.2.0-14.el8_4.3.x86_64.rpm SHA-256: 4ccd5970eed9cdac68aa621cca485763eb576876abdfbaff82cc2eeeb913bd6f
freerdp-libs-2.2.0-14.el8_4.3.i686.rpm SHA-256: 07ae71fc1cbc48a552bd357231f0616a5a88a8fe1b1bffe0fd1e8bc72697cd8a
freerdp-libs-2.2.0-14.el8_4.3.x86_64.rpm SHA-256: 075c4755c5f8f9e47e7de36eeca22d019c4d91c531eda4d9c7a3c9ae1571951e
freerdp-libs-debuginfo-2.2.0-14.el8_4.3.i686.rpm SHA-256: 3662606860e1246271d4c70f6df64f4b358cad739afd2c35a5e5028d20f7f166
freerdp-libs-debuginfo-2.2.0-14.el8_4.3.x86_64.rpm SHA-256: 56a788d3395b9211137e2bed4ffc2622879987201dc4853915562da2fad619d4
libwinpr-2.2.0-14.el8_4.3.i686.rpm SHA-256: 53bf7522c857e1c64559719caf781fc277962f45fda76be88c138ff697fc85e8
libwinpr-2.2.0-14.el8_4.3.x86_64.rpm SHA-256: d3bc5a1766da9e9d264073d8234d09d57eac646dbb1f5c963d860d5838db7fd8
libwinpr-debuginfo-2.2.0-14.el8_4.3.i686.rpm SHA-256: 0cf3a9f0c254d907c8bfdb8e47a249498cde444f6d04e722522f19812c45a5a5
libwinpr-debuginfo-2.2.0-14.el8_4.3.x86_64.rpm SHA-256: 0f6570f6385bff29c4455997a9eb17534bd3a68de9ee9b6571bee28117376582
libwinpr-devel-2.2.0-14.el8_4.3.i686.rpm SHA-256: 4a01916eed10cb6d474788073d513f63f901d94a966ee9bd4e593e81ec6e9110
libwinpr-devel-2.2.0-14.el8_4.3.x86_64.rpm SHA-256: 4f60fb144f7cc76cdd20d3ae82eb3233347bb783d0164bddc0ac176d8859e737

Red Hat Enterprise Linux Server - AUS 8.4

SRPM
freerdp-2.2.0-14.el8_4.3.src.rpm SHA-256: cea7c9b1e36196228a23074e6e724b9d0706178eb9ae8e7b114b9a8aeb7d2913
x86_64
freerdp-2.2.0-14.el8_4.3.x86_64.rpm SHA-256: 5bbd1c0b5a55daecfad8a81eba5518b20ff34a8c80a5f53446cc434b879da69f
freerdp-debuginfo-2.2.0-14.el8_4.3.i686.rpm SHA-256: 7c9ae97f6958dfce4665f1163c5760e78b2d7bffb8f67da1804e7ca1c4f7d918
freerdp-debuginfo-2.2.0-14.el8_4.3.x86_64.rpm SHA-256: 89dec8b3231000eae3654ec3e19555b0b271b73601629222b3e05801591ce706
freerdp-debugsource-2.2.0-14.el8_4.3.i686.rpm SHA-256: 12630599c1839d7d7d3f4d98c3bc6370966ff3a2c48ee529b1f77a7654a2ade0
freerdp-debugsource-2.2.0-14.el8_4.3.x86_64.rpm SHA-256: 4ccd5970eed9cdac68aa621cca485763eb576876abdfbaff82cc2eeeb913bd6f
freerdp-libs-2.2.0-14.el8_4.3.i686.rpm SHA-256: 07ae71fc1cbc48a552bd357231f0616a5a88a8fe1b1bffe0fd1e8bc72697cd8a
freerdp-libs-2.2.0-14.el8_4.3.x86_64.rpm SHA-256: 075c4755c5f8f9e47e7de36eeca22d019c4d91c531eda4d9c7a3c9ae1571951e
freerdp-libs-debuginfo-2.2.0-14.el8_4.3.i686.rpm SHA-256: 3662606860e1246271d4c70f6df64f4b358cad739afd2c35a5e5028d20f7f166
freerdp-libs-debuginfo-2.2.0-14.el8_4.3.x86_64.rpm SHA-256: 56a788d3395b9211137e2bed4ffc2622879987201dc4853915562da2fad619d4
libwinpr-2.2.0-14.el8_4.3.i686.rpm SHA-256: 53bf7522c857e1c64559719caf781fc277962f45fda76be88c138ff697fc85e8
libwinpr-2.2.0-14.el8_4.3.x86_64.rpm SHA-256: d3bc5a1766da9e9d264073d8234d09d57eac646dbb1f5c963d860d5838db7fd8
libwinpr-debuginfo-2.2.0-14.el8_4.3.i686.rpm SHA-256: 0cf3a9f0c254d907c8bfdb8e47a249498cde444f6d04e722522f19812c45a5a5
libwinpr-debuginfo-2.2.0-14.el8_4.3.x86_64.rpm SHA-256: 0f6570f6385bff29c4455997a9eb17534bd3a68de9ee9b6571bee28117376582
libwinpr-devel-2.2.0-14.el8_4.3.i686.rpm SHA-256: 4a01916eed10cb6d474788073d513f63f901d94a966ee9bd4e593e81ec6e9110
libwinpr-devel-2.2.0-14.el8_4.3.x86_64.rpm SHA-256: 4f60fb144f7cc76cdd20d3ae82eb3233347bb783d0164bddc0ac176d8859e737

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility