|
|
Log in / Subscribe / Register

SUSE alert SUSE-SU-2026:22194-1 (freerdp)

From:  SLE-SECURITY-UPDATES <null@suse.de>
To:  sle-security-updates@lists.suse.com
Subject:  SUSE-SU-2026:22194-1: important: Security update for freerdp
Date:  Tue, 23 Jun 2026 16:37:10 -0000
Message-ID:  <178223263049.221.17979660855307116295@f1988df5aa67>

# Security update for freerdp Announcement ID: SUSE-SU-2026:22194-1 Release Date: 2026-06-20T06:54:39Z Rating: important References: * bsc#1174200 * bsc#1261217 * bsc#1261222 * bsc#1261223 * bsc#1261226 * bsc#1261227 * bsc#1262743 * bsc#1266317 * bsc#1267008 * bsc#1267009 * bsc#1267010 * bsc#1267011 Cross-References: * CVE-2026-33982 * CVE-2026-33985 * CVE-2026-33986 * CVE-2026-33987 * CVE-2026-33995 * CVE-2026-40033 * CVE-2026-40254 * CVE-2026-44420 * CVE-2026-44421 * CVE-2026-44422 * CVE-2026-45700 CVSS scores: * CVE-2026-33982 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-33982 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-33982 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-33985 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-33985 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:L * CVE-2026-33985 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L * CVE-2026-33985 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:L * CVE-2026-33986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-33986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-33987 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-33987 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-33987 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H * CVE-2026-33995 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-33995 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40033 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-40033 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-40033 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40033 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-40254 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-40254 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-40254 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-40254 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-44420 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-44420 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-44421 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-44421 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-44422 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-44422 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-44422 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-45700 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45700 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-45700 ( NVD ): 7.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45700 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 11 vulnerabilities and has one fix can now be installed. ## Description: This update for freerdp fixes the following issues Update to version 3.26.0: * CVE-2026-33982: heap-buffer-overflow READ vulnerability at 24 bytes before the allocation, in winpr_aligned_offset_recalloc() (bsc#1261222). * CVE-2026-33985: FreeRDP: Information disclosure via heap memory out of bounds read (bsc#1261217). * CVE-2026-33986: heap OOB write due to H.264 YUV buffer dimension desync (bsc#1261223). * CVE-2026-33987: heap OOB write due to persistent cache bmpSize desync (bsc#1261226). * CVE-2026-33995: double-free vulnerability in kerberos_AcceptSecurityContext() and kerberos_InitializeSecurityContextA() (bsc#1261227). * CVE-2026-40033: heap buffer overflow in `gdi_CacheToSurface` allows attackers to cause a denial of service or achieve remote execute code (bsc#1266317). * CVE-2026-40254: off-by-one in contains_dotdot() allows drive channel path traversal (bsc#1262743). * CVE-2026-44420: Prior to 3.26.0, a malicious RDP client can trigger a heap- buffer-overflow write in FreeRDP's server- side clipboard (cliprdr) channel (bsc#1267008). * CVE-2026-44421: Prior to 3.26.0, a malicious RDP server can trigger a heap- buffer-overflow write in the FreeRDP client by sending crafted RDPGFX PDUs (bsc#1267009). * CVE-2026-44422: Prior to 3.26.0, a malicious-server-triggerable heap use- after-free / double-free in the FreeRDP client's RDPEAR authentication- redirection path exists (bsc#1267010). * CVE-2026-45700: n attacker can bypass the check with a large nDstStep and a large nXDst, causing planar_decompress_plane_rle() to write past the end of pTempData (bsc#1267011). Changes: * cmake: Findyuv: Use correct pkgconfig name (#12666) * Remove deallocator attribute from rfx_message_free (#12681) * [winpr,utils] improve winpr/ntlm.h (#12677) * rdpecam-v4l: stop the capture thread when streaming is cleared (#12690) * fix(winpr,ncrypt): support PIV retired key slots for smartcard logon (#12684) * [core,instance] fix deprecation guards (#12691) * [ci,alt-arch] enable internal MD4, MD5 and RC4 (#12692) * Add VideoToolbox H.264 support for ffmpeg (#12694) * [client,common] add /args-from:file: syntax (#12697) * [ci,freebsd] update freebsd builds (#12698, #12700, #12701, #12702) * [client, android] UI modernization, SQLCipher and more (#12685, #12686, #12687, #12730, * # 12731, #12736, #12737, #12688) * [cmake,deps] use alias target for sso-mib (#12706) * [core,settings] add auto reconnect triggered flag (#12709) * Force YUV420P when videotoolbox is used (#12711) * Release cleanups (#12712) * [gdi,gfx] fix bounds checks and proxy unit tests (#12713) * Improved input checks (#12714) * [winpr,utils] add unit tests for command line parser (#12716) * Cmdline fixes (#12717) * [codec,planar] fix bounds checks (#12718) * [client,common] add freerdp_client_settings_parse_command_line_argume... (#12724) * [winpr,sspi] clean up ntlm code (#12732) * Experimental AV1 support has been added. This currently works only with FreeRDP based servers. * Most notably there is now support for [MS-RDPEWA] (FIDO2 redirection) * Android client received a (small) facelift * Improved SDL3 client drawing performance * Console output support for SDL3 (windows) and windows native client * RDP proxy now supports NSCodec and RFX modes. * RDP PRoxy now has smartcard emulation and SAM file support (via config file) * Smartcard KSP support for NLA authentication * [winpr,wlog] add WLog_SetGlobalPrefix (#12497) * [channels,video] fix wrong cast (#12511) * [codec,openh264] reject encoder ABI mismatch on runtime-loaded library (#12510) * [client,sdl] create a copy of rdpPointer (#12512) * [codec,video] properly pass intermediate format (#12518) * [utils, signal] lazily initialize Windows CRITICAL_SECTION to match POSIX static mutex behavior (#12520) * winpr: improve libunwind backtraces (#12530) * [server,shadow] remember selected caps (#12528) * Zero credential data before free in NLA and NTLM context (#12532) * [server,proxy] ignore missing client in input channel (#12536) * [server,proxy] ignore rdpdr messages (#12537) * [winpr,sspi] improve kerberos logging (#12538) * Codec fixes (#12542) * [winpr,sspi] Fix context nullptr handling (#12543) * Dev 3.24.3 dev0 (#12545) * Fix memory leak in gdi_create_bitmap() on gdi_CreateBitmap failure (libfreerdp/gdi/graphics.c) (#12547) * Fix memory leak in vgids_read_do_fkt() on Stream_New failure (libfreerdp/emu/scard/smartcard_virtual_gids.c) (#12548) * Proxy config improve (#12549) * Proxy config improve (#12550) * [client,sdl] clamp cursor hotspot (#12553) * RFC: Research/av1 codec extension (#12527) * [winpr,kerberos] fix krb_log_context_encryption (#12555) * [client,sdl] fix global init return check (#12558) * Fix remote credential with windows11h2 (#12560) * Proxy scard auth improvements (#12561) * [winpr,sspi] guard krb5_get_etype_info (#12562) * [utils,smartcard] fix STATUS_BUFFER_TOO_SMALL (#12564) * [client,common] do not manipulate security settings for smartcard-logon (#12567) * [channels,audin] fix regression for microphone (#12570) * [client,sdl] add SDL_KMOD_MODE and SDL_KMOD_LEVEL5 (#12569) * Fix unbound strlen on slotDescription (#12571) * build: Update FindFFmpeg.cmake to support Apple frameworks with 'lib' prefix (#12565) * [channels,rdpewa] add WebAuthn virtual channel support (#12572) * [core] fix freerdp_get_nla_sspi_error always returning 0 on client (#12574) * [ci] enable rdpewa channel (#12576) * small refactoring (#12578) * Rdpewa unify notifications (#12581) * [client,sdl] fix crash when clicking 'cancel' on PIN popup (#12580) * [channels,drive] refine bounds checks (#12584) * fix: smartcard logon with ECC keys and minidriver-assigned container names (#12585) * Various papercuts (#12583) * fix: console output on Windows client (#12573) * [winpr,crt] dump stack on aligned memory errors (#12588) * [client,x11] keep scancode input for Ctrl/Alt/Super combinations in /kbd:unicode mode (#12590) * [codec,progressive] fix underflow guard in progressive_rfx_quant_sub (#12592) * fix: wfreerdp floatbar visibility (#12594) * [winpr,json] return a copy from WINPR_JSON_Print* (#12595) * [client,sdl] drop WITH_DEBUG_SDL_EVENTS (#12599) * Ncrypt and asn1 cleanup (#12604) * Video channel fix (#12593) * [codec,h264] fix media foundation backend (#12606) * fix(sdl): detect Hyprland and river in tryFallback() (#12608) * Proxy stress fixes (#12597) * Add new fuzzer tests (#12613) * fix(sdl): use SDL_Renderer instead of software surfaces (#12607) * fix(sdl): BFS neighbor walk pop/begin mismatch in addOrUpdateDisplay (#12614) * fix(sdl): promote first monitor as primary when subset excludes primary (#12618) * [ci,android] default to only aarch64 (#12622) * Fix process exit code on non-pidfd platforms (macOS, BSD)#12534) (#12586) * warning cleanups (#12626) * fix: prevent PostQuitMessage in RemoteApp WM_DESTROY handler (#12629) * [winpr,ntlm] fix message cleanup across the SSPI lifecycle (#12609) * Code bug fixes (#12632) * Oss fixes (#12633) * [client,android] add an option to enable keeping screen on when connected (#12630) * [client, android] Fix layout overlaps, migrate to AndroidX, and update UI components (#12628) * Proxy config tests (#12636) * Proxy config optional targethost (#12637) * [client,sdl] set SDL_HINT_SCREENSAVER_INHIBIT_ACTIVITY_NAME (#12639) * Nightly deb fix (#12640, #12641, #12649, #12650, #12642, #12643) * [winpr,input] fix korean keyboard mapping (#12646) * [client,sdl] set hints before SDL_Init (#12644) * Sdl inhibit option (#12647) * [client,X11] fix residual race in xf_clipboard_formats_free (#12648) * (sdl3): Fix oversized window on HiDPI Wayland (#12635) * [cache,bitmap] fix off-by-one in bitmap_cache_put bounds check (#12651) * [winpr,sspi] free fields buffer immediately (#12654) * [codec,dsp] fix fencepost error in dsp_ima_clamp_step (#12655) * RDPECAM MJPEG support * Support for FDK-AAC for sound and microphone redirection * Support timezones as JSON resources * Rely preferably on pkgconfig to pull devel packages instead of * A new option /cert that unifies all certificate related options (gh#FreeRDP/FreeRDP#5880) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-981=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-981=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * freerdp-3.26.0-160000.1.1 * freerdp-proxy-plugins-debuginfo-3.26.0-160000.1.1 * libfreerdp3-3-3.26.0-160000.1.1 * freerdp-sdl-debuginfo-3.26.0-160000.1.1 * libwinpr3-3-3.26.0-160000.1.1 * libwinpr3-3-debuginfo-3.26.0-160000.1.1 * freerdp-debugsource-3.26.0-160000.1.1 * freerdp-proxy-3.26.0-160000.1.1 * freerdp-proxy-debuginfo-3.26.0-160000.1.1 * freerdp-server-3.26.0-160000.1.1 * libfreerdp3-3-debuginfo-3.26.0-160000.1.1 * freerdp-server-debuginfo-3.26.0-160000.1.1 * winpr-devel-3.26.0-160000.1.1 * freerdp-devel-3.26.0-160000.1.1 * librdtk0-0-debuginfo-3.26.0-160000.1.1 * freerdp-sdl-3.26.0-160000.1.1 * libfreerdp-server-proxy3-3-3.26.0-160000.1.1 * freerdp-debuginfo-3.26.0-160000.1.1 * freerdp-wayland-3.26.0-160000.1.1 * libfreerdp-server-proxy3-3-debuginfo-3.26.0-160000.1.1 * freerdp-wayland-debuginfo-3.26.0-160000.1.1 * libuwac0-0-3.26.0-160000.1.1 * freerdp-proxy-plugins-3.26.0-160000.1.1 * libuwac0-0-debuginfo-3.26.0-160000.1.1 * librdtk0-0-3.26.0-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * freerdp-3.26.0-160000.1.1 * freerdp-proxy-plugins-debuginfo-3.26.0-160000.1.1 * libfreerdp3-3-3.26.0-160000.1.1 * freerdp-sdl-debuginfo-3.26.0-160000.1.1 * libwinpr3-3-3.26.0-160000.1.1 * libwinpr3-3-debuginfo-3.26.0-160000.1.1 * freerdp-debugsource-3.26.0-160000.1.1 * freerdp-proxy-3.26.0-160000.1.1 * freerdp-proxy-debuginfo-3.26.0-160000.1.1 * freerdp-server-3.26.0-160000.1.1 * libfreerdp3-3-debuginfo-3.26.0-160000.1.1 * freerdp-server-debuginfo-3.26.0-160000.1.1 * winpr-devel-3.26.0-160000.1.1 * freerdp-devel-3.26.0-160000.1.1 * librdtk0-0-debuginfo-3.26.0-160000.1.1 * freerdp-sdl-3.26.0-160000.1.1 * libfreerdp-server-proxy3-3-3.26.0-160000.1.1 * freerdp-debuginfo-3.26.0-160000.1.1 * freerdp-wayland-3.26.0-160000.1.1 * libfreerdp-server-proxy3-3-debuginfo-3.26.0-160000.1.1 * freerdp-wayland-debuginfo-3.26.0-160000.1.1 * libuwac0-0-3.26.0-160000.1.1 * freerdp-proxy-plugins-3.26.0-160000.1.1 * libuwac0-0-debuginfo-3.26.0-160000.1.1 * librdtk0-0-3.26.0-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33982.html * https://www.suse.com/security/cve/CVE-2026-33985.html * https://www.suse.com/security/cve/CVE-2026-33986.html * https://www.suse.com/security/cve/CVE-2026-33987.html * https://www.suse.com/security/cve/CVE-2026-33995.html * https://www.suse.com/security/cve/CVE-2026-40033.html * https://www.suse.com/security/cve/CVE-2026-40254.html * https://www.suse.com/security/cve/CVE-2026-44420.html * https://www.suse.com/security/cve/CVE-2026-44421.html * https://www.suse.com/security/cve/CVE-2026-44422.html * https://www.suse.com/security/cve/CVE-2026-45700.html * https://bugzilla.suse.com/show_bug.cgi?id=1174200 * https://bugzilla.suse.com/show_bug.cgi?id=1261217 * https://bugzilla.suse.com/show_bug.cgi?id=1261222 * https://bugzilla.suse.com/show_bug.cgi?id=1261223 * https://bugzilla.suse.com/show_bug.cgi?id=1261226 * https://bugzilla.suse.com/show_bug.cgi?id=1261227 * https://bugzilla.suse.com/show_bug.cgi?id=1262743 * https://bugzilla.suse.com/show_bug.cgi?id=1266317 * https://bugzilla.suse.com/show_bug.cgi?id=1267008 * https://bugzilla.suse.com/show_bug.cgi?id=1267009 * https://bugzilla.suse.com/show_bug.cgi?id=1267010 * https://bugzilla.suse.com/show_bug.cgi?id=1267011


Attachment: None (type=text/html)

(HTML attachment elided)


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds