RHSA-2026:54667: Important: freerdp security update
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.Security Fix(es): FreeRDP: FreeRDP: Remote code execution via heap out-of-bounds write in RemoteFX decoding (CVE-2026-55827) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/freerdpto a version that resolves this vulnerability.Fixed in 3.10.3-3.el10_0.10 - Upgrade
Upgrade
redhat/freerdp-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.3-3.el10_0.10 - Upgrade
Upgrade
redhat/freerdp-debugsourceto a version that resolves this vulnerability.Fixed in 3.10.3-3.el10_0.10 - Upgrade
Upgrade
redhat/freerdp-libsto a version that resolves this vulnerability.Fixed in 3.10.3-3.el10_0.10 - Upgrade
Upgrade
redhat/freerdp-libs-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.3-3.el10_0.10 - Upgrade
Upgrade
redhat/freerdp-server-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.3-3.el10_0.10 - Upgrade
Upgrade
redhat/libwinprto a version that resolves this vulnerability.Fixed in 3.10.3-3.el10_0.10 - Upgrade
Upgrade
redhat/libwinpr-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.3-3.el10_0.10 - Upgrade
Upgrade
redhat/freerdpto a version that resolves this vulnerability.Fixed in 3.10.3-3.el10_0.10.aa - Upgrade
Upgrade
redhat/freerdp-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.3-3.el10_0.10.aa - Upgrade
Upgrade
redhat/freerdp-debugsourceto a version that resolves this vulnerability.Fixed in 3.10.3-3.el10_0.10.aa - Upgrade
Upgrade
redhat/freerdp-libsto a version that resolves this vulnerability.Fixed in 3.10.3-3.el10_0.10.aa - Upgrade
Upgrade
redhat/freerdp-libs-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.3-3.el10_0.10.aa - Upgrade
Upgrade
redhat/freerdp-server-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.3-3.el10_0.10.aa - Upgrade
Upgrade
redhat/libwinprto a version that resolves this vulnerability.Fixed in 3.10.3-3.el10_0.10.aa - Upgrade
Upgrade
redhat/libwinpr-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.3-3.el10_0.10.aa - Upgrade
Upgrade
redhat/freerdp-develto a version that resolves this vulnerability.Fixed in 3.10.3-3.el10_0.10 - Upgrade
Upgrade
redhat/freerdp-serverto a version that resolves this vulnerability.Fixed in 3.10.3-3.el10_0.10 - Upgrade
Upgrade
redhat/libwinpr-develto a version that resolves this vulnerability.Fixed in 3.10.3-3.el10_0.10 - Upgrade
Upgrade
redhat/freerdp-develto a version that resolves this vulnerability.Fixed in 3.10.3-3.el10_0.10.aa - Upgrade
Upgrade
redhat/freerdp-serverto a version that resolves this vulnerability.Fixed in 3.10.3-3.el10_0.10.aa - Upgrade
Upgrade
redhat/libwinpr-develto a version that resolves this vulnerability.Fixed in 3.10.3-3.el10_0.10.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:54667?
The severity of RHSA-2026:54667 is rated as high with a score of 7.
What software is affected by RHSA-2026:54667?
The affected software includes freerdp, freerdp-debuginfo, freerdp-debugsource, and related libraries.
How do I fix RHSA-2026:54667?
To fix RHSA-2026:54667, update the affected FreeRDP packages to the latest version provided by Red Hat.
What kind of vulnerability is addressed in RHSA-2026:54667?
RHSA-2026:54667 addresses a remote code execution vulnerability due to a heap out-of-bounds write.
Why is RHSA-2026:54667 considered important?
RHSA-2026:54667 is considered important due to its potential for remote code execution, which can compromise the security of affected systems.