RHSA-2026:54486: Important: freerdp security update
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.Security Fix(es): FreeRDP: FreeRDP: Remote code execution or denial of service via heap-based buffer overflow (CVE-2026-64620) FreeRDP: FreeRDP: Double-free vulnerability via crafted .rdp file leading to potential remote code execution (CVE-2026-64621) FreeRDP: FreeRDP: Arbitrary code execution via malicious RDP files (CVE-2026-64624) FreeRDP: FreeRDP: Denial of Service via crafted WindowIcon async message (CVE-2026-67299) FreeRDP: FreeRDP: HTTP Proxy Request Injection via Redirection (CVE-2026-67289) FreeRDP: FreeRDP: Remote code execution or denial of service via audio input integer overflow (CVE-2026-68580) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/freerdpto a version that resolves this vulnerability.Fixed in 3.10.3-12.el10_2.8 - Upgrade
Upgrade
redhat/freerdp-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.3-12.el10_2.8 - Upgrade
Upgrade
redhat/freerdp-debugsourceto a version that resolves this vulnerability.Fixed in 3.10.3-12.el10_2.8 - Upgrade
Upgrade
redhat/freerdp-libsto a version that resolves this vulnerability.Fixed in 3.10.3-12.el10_2.8 - Upgrade
Upgrade
redhat/freerdp-libs-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.3-12.el10_2.8 - Upgrade
Upgrade
redhat/freerdp-server-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.3-12.el10_2.8 - Upgrade
Upgrade
redhat/libwinprto a version that resolves this vulnerability.Fixed in 3.10.3-12.el10_2.8 - Upgrade
Upgrade
redhat/libwinpr-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.3-12.el10_2.8 - Upgrade
Upgrade
redhat/freerdpto a version that resolves this vulnerability.Fixed in 3.10.3-12.el10_2.8.aa - Upgrade
Upgrade
redhat/freerdp-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.3-12.el10_2.8.aa - Upgrade
Upgrade
redhat/freerdp-debugsourceto a version that resolves this vulnerability.Fixed in 3.10.3-12.el10_2.8.aa - Upgrade
Upgrade
redhat/freerdp-libsto a version that resolves this vulnerability.Fixed in 3.10.3-12.el10_2.8.aa - Upgrade
Upgrade
redhat/freerdp-libs-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.3-12.el10_2.8.aa - Upgrade
Upgrade
redhat/freerdp-server-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.3-12.el10_2.8.aa - Upgrade
Upgrade
redhat/libwinprto a version that resolves this vulnerability.Fixed in 3.10.3-12.el10_2.8.aa - Upgrade
Upgrade
redhat/libwinpr-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.3-12.el10_2.8.aa - Upgrade
Upgrade
redhat/freerdp-develto a version that resolves this vulnerability.Fixed in 3.10.3-12.el10_2.8 - Upgrade
Upgrade
redhat/freerdp-serverto a version that resolves this vulnerability.Fixed in 3.10.3-12.el10_2.8 - Upgrade
Upgrade
redhat/libwinpr-develto a version that resolves this vulnerability.Fixed in 3.10.3-12.el10_2.8 - Upgrade
Upgrade
redhat/freerdp-develto a version that resolves this vulnerability.Fixed in 3.10.3-12.el10_2.8.aa - Upgrade
Upgrade
redhat/freerdp-serverto a version that resolves this vulnerability.Fixed in 3.10.3-12.el10_2.8.aa - Upgrade
Upgrade
redhat/libwinpr-develto a version that resolves this vulnerability.Fixed in 3.10.3-12.el10_2.8.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:54486?
The severity of RHSA-2026:54486 is categorized as high with a severity score of 7.
What vulnerabilities does RHSA-2026:54486 address?
RHSA-2026:54486 addresses a buffer overflow and integer overflow vulnerabilities that may lead to remote code execution or denial of service.
How do I fix RHSA-2026:54486?
To fix RHSA-2026:54486, you should update the FreeRDP packages to the latest version available from Red Hat.
What product is affected by RHSA-2026:54486?
RHSA-2026:54486 affects the FreeRDP implementation, including its client and server components.
What is the potential impact of not addressing RHSA-2026:54486?
Not addressing RHSA-2026:54486 could lead to severe security risks, including remote code execution and denial of service attacks.