RHSA-2026:61250: Important: freerdp security update
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.Security Fix(es): FreeRDP: FreeRDP: Arbitrary code execution via malicious RDP files (CVE-2026-64624) FreeRDP: FreeRDP: Denial of Service via crafted WindowIcon async message (CVE-2026-67299) FreeRDP: FreeRDP: HTTP Proxy Request Injection via Redirection (CVE-2026-67289) FreeRDP: FreeRDP: Remote code execution or denial of service via audio input integer overflow (CVE-2026-68580) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/freerdpto a version that resolves this vulnerability.Fixed in 2.2.0-7.el8_6.11 - Upgrade
Upgrade
redhat/freerdp-debuginfoto a version that resolves this vulnerability.Fixed in 2.2.0-7.el8_6.11 - Upgrade
Upgrade
redhat/freerdp-debugsourceto a version that resolves this vulnerability.Fixed in 2.2.0-7.el8_6.11 - Upgrade
Upgrade
redhat/freerdp-libsto a version that resolves this vulnerability.Fixed in 2.2.0-7.el8_6.11 - Upgrade
Upgrade
redhat/freerdp-libs-debuginfoto a version that resolves this vulnerability.Fixed in 2.2.0-7.el8_6.11 - Upgrade
Upgrade
redhat/libwinprto a version that resolves this vulnerability.Fixed in 2.2.0-7.el8_6.11 - Upgrade
Upgrade
redhat/libwinpr-debuginfoto a version that resolves this vulnerability.Fixed in 2.2.0-7.el8_6.11 - Upgrade
Upgrade
redhat/libwinpr-develto a version that resolves this vulnerability.Fixed in 2.2.0-7.el8_6.11 - Upgrade
Upgrade
FreeRDPto a version that resolves this vulnerability.Patch FreeRDP: Denial of Service via crafted WindowIcon async message (CVE-2026-67299) - Upgrade
Upgrade
FreeRDPto a version that resolves this vulnerability.Patch FreeRDP: HTTP Proxy Request Injection via Redirection (CVE-2026-67289) - Upgrade
Upgrade
FreeRDPto a version that resolves this vulnerability.Patch FreeRDP: Remote code execution or denial of service via audio input integer overflow (CVE-2026-68580) - Upgrade
Upgrade
FreeRDPto a version that resolves this vulnerability.Patch FreeRDP: Arbitrary code execution via malicious RDP files (CVE-2026-64624)
Event History
Frequently Asked Questions
Which systems should be prioritized for this update?
Prioritize systems that use the xfreerdp client to connect to RDP servers, including Microsoft Windows machines, xrdp, or VirtualBox, and systems with the listed FreeRDP or WinPR packages installed.
What attacker-controlled inputs are implicated by the fixes?
The advisory identifies malicious RDP files, crafted WindowIcon asynchronous messages, proxy redirection handling, and audio input as affected inputs. The reported impacts include arbitrary code execution, remote code execution, denial of service, and HTTP proxy request injection.
Which installed packages are covered by this advisory?
The listed packages are freerdp, freerdp-debuginfo, freerdp-debugsource, freerdp-libs, freerdp-libs-debuginfo, libwinpr, libwinpr-debuginfo, and libwinpr-devel.