Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:6712 - Security Advisory
Issued:
2026-04-06
Updated:
2026-04-06

RHSA-2026:6712 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: freerdp security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for freerdp is now available for Red Hat Enterprise Linux 8.2 Advanced Update Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.

Security Fix(es):

  • freerdp: FreeRDP: Arbitrary code execution via heap out-of-bounds write in RLE planar decode path (CVE-2026-26965)
  • freerdp: FreeRDP: Arbitrary code execution via heap buffer overflow in GDI surface pipeline (CVE-2026-26955)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - AUS 8.2 x86_64

Fixes

  • BZ - 2442959 - CVE-2026-26965 freerdp: FreeRDP: Arbitrary code execution via heap out-of-bounds write in RLE planar decode path
  • BZ - 2443132 - CVE-2026-26955 freerdp: FreeRDP: Arbitrary code execution via heap buffer overflow in GDI surface pipeline

CVEs

  • CVE-2026-26955
  • CVE-2026-26965

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - AUS 8.2

SRPM
freerdp-2.0.0-46.rc4.el8_2.8.src.rpm SHA-256: 0a3bbc03a013a8d2675d795f6aa61fc0769b5ff4a63f5205f814935ed4182505
x86_64
freerdp-2.0.0-46.rc4.el8_2.8.x86_64.rpm SHA-256: 9bfd608946e1ef4c4f52175ff1ee9e3595e745a163b5f5d5367230f1ca81ca6d
freerdp-debuginfo-2.0.0-46.rc4.el8_2.8.i686.rpm SHA-256: a3a90084a40151e104f4e03aa66c3ef4827e53cb49c4af211cd831aeaef07160
freerdp-debuginfo-2.0.0-46.rc4.el8_2.8.x86_64.rpm SHA-256: 82d1ecd39ce59219f3f0ceb3db6a8c33d366eab30a0aac5b758db6320ab01476
freerdp-debugsource-2.0.0-46.rc4.el8_2.8.i686.rpm SHA-256: b078ef186efaef9c69a90ea42f65aeb2c60c5f294ecffca60d72da5e128b7495
freerdp-debugsource-2.0.0-46.rc4.el8_2.8.x86_64.rpm SHA-256: 05149904add78bc3ef4c8962122b7624a47b426e30ceab7bfe75aa6b1d94cb48
freerdp-libs-2.0.0-46.rc4.el8_2.8.i686.rpm SHA-256: d33091fddbf6fcb4db0e7ff0072647a38f5d0263e7cf4a10342b145639ed4949
freerdp-libs-2.0.0-46.rc4.el8_2.8.x86_64.rpm SHA-256: 03dfa0015d5e1283b34a9730707ce9b04080da6592e732eccc37da51e3fcca6a
freerdp-libs-debuginfo-2.0.0-46.rc4.el8_2.8.i686.rpm SHA-256: 774898afd63b19882feedd31d02ad254b483c98e56547013ce584f57ed8b7f0d
freerdp-libs-debuginfo-2.0.0-46.rc4.el8_2.8.x86_64.rpm SHA-256: 42b7f27f7e9e72474f15db440d77734473309a2a0d80535ef68b70e91cefd14d
libwinpr-2.0.0-46.rc4.el8_2.8.i686.rpm SHA-256: 573c0a58a4050f50a167cc3e8f83acb9c152ff0882ba9117208f31c966d485ab
libwinpr-2.0.0-46.rc4.el8_2.8.x86_64.rpm SHA-256: f22f175423a44aff3406eb8e9cde274ff24018c6d85d8ac08e223e33465293fb
libwinpr-debuginfo-2.0.0-46.rc4.el8_2.8.i686.rpm SHA-256: 811cbcd880e20612612f8426bb4c99d30e93418490e63cc9981d87b3c584e4b3
libwinpr-debuginfo-2.0.0-46.rc4.el8_2.8.x86_64.rpm SHA-256: 1c74320e816fab8ee2237dacf5348906c56ed9186a38a0f63b349f676ae067d7
libwinpr-devel-2.0.0-46.rc4.el8_2.8.i686.rpm SHA-256: 092a00b306aa7681c3762ec0f61d08b6351af069657a6cff5db6daef7a59781c
libwinpr-devel-2.0.0-46.rc4.el8_2.8.x86_64.rpm SHA-256: 18ede7a320a2c19562d2b63ad44519af42ef3595b0243f79b49743004476e023

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility