Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:6616 - Security Advisory
Issued:
2026-04-06
Updated:
2026-04-06

RHSA-2026:6616 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: freerdp security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for freerdp is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.

Security Fix(es):

  • freerdp: FreeRDP: Arbitrary code execution via heap out-of-bounds write in RLE planar decode path (CVE-2026-26965)
  • freerdp: FreeRDP: Arbitrary code execution via heap buffer overflow in GDI surface pipeline (CVE-2026-26955)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4 x86_64
  • Red Hat Enterprise Linux Server - AUS 8.4 x86_64

Fixes

  • BZ - 2442959 - CVE-2026-26965 freerdp: FreeRDP: Arbitrary code execution via heap out-of-bounds write in RLE planar decode path
  • BZ - 2443132 - CVE-2026-26955 freerdp: FreeRDP: Arbitrary code execution via heap buffer overflow in GDI surface pipeline

CVEs

  • CVE-2026-26955
  • CVE-2026-26965

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4

SRPM
freerdp-2.2.0-10.el8_4.src.rpm SHA-256: fd60a77070ddbe8a3361f36634f8dc68d7270a6a9c093bfc838ec2e9e41970e1
x86_64
freerdp-2.2.0-10.el8_4.x86_64.rpm SHA-256: 82780f5a8415a7acf83045f06a1c55ea118ac5f2c7e14bea00cec5361a4812c5
freerdp-debuginfo-2.2.0-10.el8_4.i686.rpm SHA-256: 467e7f5bfc06e56fb20d8c6ff1f111e6066719a189c53fc76782a170b5be9177
freerdp-debuginfo-2.2.0-10.el8_4.x86_64.rpm SHA-256: f96bce2387beb0feeb7836c7a7b5ad579f2e57c7e2e2163121839a3ba0abb968
freerdp-debugsource-2.2.0-10.el8_4.i686.rpm SHA-256: 57ee09b31a5df80a67c168f246590f8f009d27be650e386941fc9204ab298815
freerdp-debugsource-2.2.0-10.el8_4.x86_64.rpm SHA-256: 2523e28dc6c8fa6e26c1b541bce92143c310d09cc27b050c7cfeddcf3087bd25
freerdp-libs-2.2.0-10.el8_4.i686.rpm SHA-256: 5fd0abed34069265ae5b1caba7af58faadd80016febe8f6b15c64a2dc310cd6a
freerdp-libs-2.2.0-10.el8_4.x86_64.rpm SHA-256: 136764a90775e1b6a7fd1503754e226ef0980df55482a641d05bd3a85b559af0
freerdp-libs-debuginfo-2.2.0-10.el8_4.i686.rpm SHA-256: 1587e3142492b6e8c77a0e3e7f99e753592049981a8ad1d79d546611e85876e8
freerdp-libs-debuginfo-2.2.0-10.el8_4.x86_64.rpm SHA-256: 21c140737fa62dac3ba6298969823998c71dcc8df7e1d5e4375d48c428254e96
libwinpr-2.2.0-10.el8_4.i686.rpm SHA-256: 729f0dcf4b9b7bb1325be540846f5cbd561b7176b8cacc3060b91a0d685651a7
libwinpr-2.2.0-10.el8_4.x86_64.rpm SHA-256: 91e1146cd30104884575b89f6e929e86d0c4e1da61cc42d9d092a119f8c839ae
libwinpr-debuginfo-2.2.0-10.el8_4.i686.rpm SHA-256: 1f759dbac0740d1314d6783d74ff9d5d53b4d286343ff9823cda2c497c5387e5
libwinpr-debuginfo-2.2.0-10.el8_4.x86_64.rpm SHA-256: 578b5a8ee32569a0b9b6d8ee118120002a2cd005b391b457ee9ec41a28471b94
libwinpr-devel-2.2.0-10.el8_4.i686.rpm SHA-256: 658cda1fe2a2e42ec869089e6bcf8b7eac2200d70365e6f6030913ecb3dc39b6
libwinpr-devel-2.2.0-10.el8_4.x86_64.rpm SHA-256: deb7c72ac03bd6ad05cc24556d83c0ff2d4f9fc05f810a48f8422bc3bbf9edaf

Red Hat Enterprise Linux Server - AUS 8.4

SRPM
freerdp-2.2.0-10.el8_4.src.rpm SHA-256: fd60a77070ddbe8a3361f36634f8dc68d7270a6a9c093bfc838ec2e9e41970e1
x86_64
freerdp-2.2.0-10.el8_4.x86_64.rpm SHA-256: 82780f5a8415a7acf83045f06a1c55ea118ac5f2c7e14bea00cec5361a4812c5
freerdp-debuginfo-2.2.0-10.el8_4.i686.rpm SHA-256: 467e7f5bfc06e56fb20d8c6ff1f111e6066719a189c53fc76782a170b5be9177
freerdp-debuginfo-2.2.0-10.el8_4.x86_64.rpm SHA-256: f96bce2387beb0feeb7836c7a7b5ad579f2e57c7e2e2163121839a3ba0abb968
freerdp-debugsource-2.2.0-10.el8_4.i686.rpm SHA-256: 57ee09b31a5df80a67c168f246590f8f009d27be650e386941fc9204ab298815
freerdp-debugsource-2.2.0-10.el8_4.x86_64.rpm SHA-256: 2523e28dc6c8fa6e26c1b541bce92143c310d09cc27b050c7cfeddcf3087bd25
freerdp-libs-2.2.0-10.el8_4.i686.rpm SHA-256: 5fd0abed34069265ae5b1caba7af58faadd80016febe8f6b15c64a2dc310cd6a
freerdp-libs-2.2.0-10.el8_4.x86_64.rpm SHA-256: 136764a90775e1b6a7fd1503754e226ef0980df55482a641d05bd3a85b559af0
freerdp-libs-debuginfo-2.2.0-10.el8_4.i686.rpm SHA-256: 1587e3142492b6e8c77a0e3e7f99e753592049981a8ad1d79d546611e85876e8
freerdp-libs-debuginfo-2.2.0-10.el8_4.x86_64.rpm SHA-256: 21c140737fa62dac3ba6298969823998c71dcc8df7e1d5e4375d48c428254e96
libwinpr-2.2.0-10.el8_4.i686.rpm SHA-256: 729f0dcf4b9b7bb1325be540846f5cbd561b7176b8cacc3060b91a0d685651a7
libwinpr-2.2.0-10.el8_4.x86_64.rpm SHA-256: 91e1146cd30104884575b89f6e929e86d0c4e1da61cc42d9d092a119f8c839ae
libwinpr-debuginfo-2.2.0-10.el8_4.i686.rpm SHA-256: 1f759dbac0740d1314d6783d74ff9d5d53b4d286343ff9823cda2c497c5387e5
libwinpr-debuginfo-2.2.0-10.el8_4.x86_64.rpm SHA-256: 578b5a8ee32569a0b9b6d8ee118120002a2cd005b391b457ee9ec41a28471b94
libwinpr-devel-2.2.0-10.el8_4.i686.rpm SHA-256: 658cda1fe2a2e42ec869089e6bcf8b7eac2200d70365e6f6030913ecb3dc39b6
libwinpr-devel-2.2.0-10.el8_4.x86_64.rpm SHA-256: deb7c72ac03bd6ad05cc24556d83c0ff2d4f9fc05f810a48f8422bc3bbf9edaf

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility