RHSA-2026:47201: Important: freerdp security update
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.Security Fix(es): freerdp: FreeRDP: Out-of-bounds write in planar bitmap decoder allows arbitrary code execution (CVE-2026-45700) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/freerdpto a version that resolves this vulnerability.Fixed in 2.1.1-5.el7_9.10 - Upgrade
Upgrade
redhat/freerdp-debuginfoto a version that resolves this vulnerability.Fixed in 2.1.1-5.el7_9.10 - Upgrade
Upgrade
redhat/freerdp-develto a version that resolves this vulnerability.Fixed in 2.1.1-5.el7_9.10 - Upgrade
Upgrade
redhat/freerdp-libsto a version that resolves this vulnerability.Fixed in 2.1.1-5.el7_9.10 - Upgrade
Upgrade
redhat/libwinprto a version that resolves this vulnerability.Fixed in 2.1.1-5.el7_9.10 - Upgrade
Upgrade
redhat/libwinpr-develto a version that resolves this vulnerability.Fixed in 2.1.1-5.el7_9.10
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:47201?
The severity of RHSA-2026:47201 is classified as high with a score of 7.
How do I fix RHSA-2026:47201?
To fix RHSA-2026:47201, apply the latest security update for FreeRDP as provided by Red Hat.
What security vulnerability is addressed in RHSA-2026:47201?
RHSA-2026:47201 addresses an out-of-bounds write vulnerability in the planar bitmap decoder of FreeRDP.
Which software packages are affected by RHSA-2026:47201?
The affected software packages include freerdp, freerdp-debuginfo, freerdp-devel, freerdp-libs, libwinpr, and libwinpr-devel.
When was RHSA-2026:47201 published?
RHSA-2026:47201 was published on July 28, 2026.