Red Hat Product Errata RHSA-2026:8945 - Security Advisory Issued: 2026-04-20 Updated: 2026-04-20 RHSA-2026:8945 - Security Advisory Overview Updated Packages Synopsis Important: freerdp security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for freerdp is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox. Security Fix(es): FreeRDP: FreeRDP: Heap buffer overflow allows arbitrary code execution via crafted pixel data (CVE-2026-33984) FreeRDP: FreeRDP: Denial of Service via specially crafted Remote Desktop Protocol messages (CVE-2026-33983) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 8 x86_64 Red Hat Enterprise Linux for IBM z Systems 8 s390x Red Hat Enterprise Linux for Power, little endian 8 ppc64le Red Hat Enterprise Linux for ARM 64 8 aarch64 Red Hat CodeReady Linux Builder for x86_64 8 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 8 ppc64le Red Hat CodeReady Linux Builder for ARM 64 8 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x Fixes BZ - 2453219 - CVE-2026-33984 FreeRDP: FreeRDP: Heap buffer overflow allows arbitrary code execution via crafted pixel data BZ - 2453220 - CVE-2026-33983 FreeRDP: FreeRDP: Denial of Service via specially crafted Remote Desktop Protocol messages CVEs CVE-2026-33983 CVE-2026-33984 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 8 SRPM freerdp-2.11.7-7.el8_10.src.rpm SHA-256: 0da3f07724432036499b8aca169bcc73e65d0f4c807dd5336d7701cf65047a99 x86_64 freerdp-2.11.7-7.el8_10.x86_64.rpm SHA-256: 6e6096fcd9935ab825ac46bf1dcf1cdf7e7fa0470cbb621dfe5616b1fbc6e856 freerdp-debuginfo-2.11.7-7.el8_10.i686.rpm SHA-256: 235c9b8f8fd2be632a36accc7c982e937a7d958178ed3b2e50b13d16b743d7cd freerdp-debuginfo-2.11.7-7.el8_10.x86_64.rpm SHA-256: fabf9a6a7b0ef5063ec623216bf475f70af8f17aba8ed9349fb552e97728e968 freerdp-debugsource-2.11.7-7.el8_10.i686.rpm SHA-256: 1f6465f8f003778bc22292023a9b0046307aa191eea61e5b6af475d88b019bd9 freerdp-debugsource-2.11.7-7.el8_10.x86_64.rpm SHA-256: ff06e24c6477a7230576febba0083d372b0fe71d552741d26c0f5fbe47668645 freerdp-libs-2.11.7-7.el8_10.i686.rpm SHA-256: 8da934869e016dfc43decac42833f6ba64a1d1e56777a85b2cd1247e1ca001bc freerdp-libs-2.11.7-7.el8_10.x86_64.rpm SHA-256: f931040605add0cddcb01825030b06ff29ab65067a96e5a93ba01a402998cafe freerdp-libs-debuginfo-2.11.7-7.el8_10.i686.rpm SHA-256: 7df63258ba95e6ffa1dfff978da4b305fc7eb43586930846b14ccf1ab1b22344 freerdp-libs-debuginfo-2.11.7-7.el8_10.x86_64.rpm SHA-256: 9e9b124ca9aa55211843865fe3ed71c5e88d358171ed6bd59d75212e7229cbc7 libwinpr-2.11.7-7.el8_10.i686.rpm SHA-256: 3f3a6ee71d3797332835cec2718939b948ea589afca416a2df4f123c0d8377ad libwinpr-2.11.7-7.el8_10.x86_64.rpm SHA-256: a1baefc263912b5895aff75cdd6a7fd7aef411bd72793e11558f3aefa392e869 libwinpr-debuginfo-2.11.7-7.el8_10.i686.rpm SHA-256: feef745c14d00b1aeda93616c1a7ad382571744f394c08e73728471b243b16b5 libwinpr-debuginfo-2.11.7-7.el8_10.x86_64.rpm SHA-256: c6fbb9cbf7f8853e219a61c8103de939f35f8a9ac7434d8b531b360ba4685192 libwinpr-devel-2.11.7-7.el8_10.i686.rpm SHA-256: 7dd48c4d84d23cbe06b5e875b7a301a46ab12490eb4815cd3452957ad37e2737 libwinpr-devel-2.11.7-7.el8_10.x86_64.rpm SHA-256: 724a7ca51bff0db48ba0d515ace0d9fe296df91dd6bbffcfbd9a65e2a2d9759c Red Hat Enterprise Linux for IBM z Systems 8 SRPM freerdp-2.11.7-7.el8_10.src.rpm SHA-256: 0da3f07724432036499b8aca169bcc73e65d0f4c807dd5336d7701cf65047a99 s390x freerdp-2.11.7-7.el8_10.s390x.rpm SHA-256: 1fc47397921a3cbb44a126b198ad26e2575236a38d395aeb294dc4543e390980 freerdp-debuginfo-2.11.7-7.el8_10.s390x.rpm SHA-256: 290527b72c8aae581b2ded8e01e477381dbf18e85bf8fb282a8b008df5132b70 freerdp-debugsource-2.11.7-7.el8_10.s390x.rpm SHA-256: 245cd51e578a8bbcf10c745856ca3090aaecb576aee7ee91d0660aa785e4245a freerdp-libs-2.11.7-7.el8_10.s390x.rpm SHA-256: 7c93d1072bc9344c4e6d4485e9ba79ae04d4585d16efc3613c88dc47af9393ce freerdp-libs-debuginfo-2.11.7-7.el8_10.s390x.rpm SHA-256: 011fa95cad6c51b0f4e66f76e4d90cbba781eb2c2212c5591aef2e3290f56eb6 libwinpr-2.11.7-7.el8_10.s390x.rpm SHA-256: dfba9f5dd914e1909ddee443b84ad9cfb49ef168839bf8d8b90b03122a9d5119 libwinpr-debuginfo-2.11.7-7.el8_10.s390x.rpm SHA-256: 1789bb4ce9e56add190b0362221659e250e1c38be243a884522146a43bd50716 libwinpr-devel-2.11.7-7.el8_10.s390x.rpm SHA-256: 4051290639fb8238a8bb5819b5389e010d6c8de5a4a366f6e862a4f5afddac74 Red Hat Enterprise Linux for Power, little endian 8 SRPM freerdp-2.11.7-7.el8_10.src.rpm SHA-256: 0da3f07724432036499b8aca169bcc73e65d0f4c807dd5336d7701cf65047a99 ppc64le freerdp-2.11.7-7.el8_10.ppc64le.rpm SHA-256: b97b81c7b04252f41c9729a90a27ad61172b4b4532505e389791d9c6cd3f3dd4 freerdp-debuginfo-2.11.7-7.el8_10.ppc64le.rpm SHA-256: 513bf6ed12b441cd5ee3f0f09d17bb5c92a06fc2a092dadae064cd51d0f9839f freerdp-debugsource-2.11.7-7.el8_10.ppc64le.rpm SHA-256: 9e236d516f494afc0dc7e0fbb49d57493a63c210bfd5b29f30abae77c7766190 freerdp-libs-2.11.7-7.el8_10.ppc64le.rpm SHA-256: fe8a9d5c711d43f529d1b745cedd8bc038da19f42da370a91f625ae3ee75fced freerdp-libs-debuginfo-2.11.7-7.el8_10.ppc64le.rpm SHA-256: 73c9e6f5c46c3c4645ca8c1fdbccf86a3e14a99ce2e13e6d675a3b7d7f203980 libwinpr-2.11.7-7.el8_10.ppc64le.rpm SHA-256: 0fd6a022258da3db93e2168cb8d4ed6b03f427dce263932f8afcf4a041ad0240 libwinpr-debuginfo-2.11.7-7.el8_10.ppc64le.rpm SHA-256: b4f080667964dec2e1c7e9ee79b709a15536260de869b357896c616d1ae59eab libwinpr-devel-2.11.7-7.el8_10.ppc64le.rpm SHA-256: ff3e780104dd0a107c3daaaafb34e732d177be60bea60f8af18b5c4f25d38251 Red Hat Enterprise Linux for ARM 64 8 SRPM freerdp-2.11.7-7.el8_10.src.rpm SHA-256: 0da3f07724432036499b8aca169bcc73e65d0f4c807dd5336d7701cf65047a99 aarch64 freerdp-2.11.7-7.el8_10.aarch64.rpm SHA-256: 9390f9eaf1559767cafc35069cecf14996b34b2bcdcd9e6d14538fd643285ca2 freerdp-debuginfo-2.11.7-7.el8_10.aarch64.rpm SHA-256: b40777dbb8d25e3cbb3363f67938b152cbd089a8819c66f5aa61bee7f2146608 freerdp-debugsource-2.11.7-7.el8_10.aarch64.rpm SHA-256: c294d4ffab4343c10787dc89e3f7d126a151b3a66c0bb8b043cd1423ce1f64e7 freerdp-libs-2.11.7-7.el8_10.aarch64.rpm SHA-256: 710b94fcb13e20b4e1bdac157bf41af850c2ccd2f1844ebdebecf524b29a2d5d freerdp-libs-debuginfo-2.11.7-7.el8_10.aarch64.rpm SHA-256: 869bfd98241b51dca41f53486551a2d1bf138a3deb1d30e89b4dd04afdaa7cc7 libwinpr-2.11.7-7.el8_10.aarch64.rpm SHA-256: 73e1de1f66b221ff763db928393729456ab7cfe54e33d560d93d06b474f02321 libwinpr-debuginfo-2.11.7-7.el8_10.aarch64.rpm SHA-256: 56b7b3765b279b58fb568ebdebbff6207e7c7c86856ca29c0ead73dada83ff99 libwinpr-devel-2.11.7-7.el8_10.aarch64.rpm SHA-256: ba571bcb8cf4277e0b5680437d80cce4ee99f291e6a6b901a5cb2f3f622c83f9 Red Hat CodeReady Linux Builder for x86_64 8 SRPM x86_64 freerdp-debuginfo-2.11.7-7.el8_10.i686.rpm SHA-256: 235c9b8f8fd2be632a36accc7c982e937a7d958178ed3b2e50b13d16b743d7cd freerdp-debuginfo-2.11.7-7.el8_10.x86_64.rpm SHA-256: fabf9a6a7b0ef5063ec623216bf475f70af8f17aba8ed9349fb552e97728e968 freerdp-debugsource-2.11.7-7.el8_10.i686.rpm SHA-256: 1f6465f8f003778bc22292023a9b0046307aa191eea61e5b6af475d88b019bd9 freerdp-debugsource-2.11.7-7.el8_10.x86_64.rpm SHA-256: ff06e24c6477a7230576febba0083d372b0fe71d552741d26c0f5fbe47668645 freerdp-devel-2.11.7-7.el8_10.i686.rpm SHA-256: 9b3d5596597fa4f0c1feca67a5658f3ad62f7792ded9109ef51e62661dbcfd56 freerdp-devel-2.11.7-7.el8_10.x86_64.rpm SHA-256: a03ac5cf0bc9e22ea1e5cd28a3ff069ef2f1ed068a1f0c00e687687da7ce3674 freerdp-libs-debuginfo-2.11.7-7.el8_10.i686.rpm SHA-256: 7df63258ba95e6ffa1dfff978da4b305fc7eb43586930846b14ccf1ab1b22344 freerdp-libs-debuginfo-2.11.7-7.el8_10.x86_64.rpm SHA-256: 9e9b124ca9aa55211843865fe3ed71c5e88d358171ed6bd59d75212e7229cbc7 libwinpr-debuginfo-2.11.7-7.el8_10.i686.rpm SHA-256: feef745c14d00b1aeda93616c1a7ad382571744f394c08e73728471b243b16b5 libwinpr-debuginfo-2.11.7-7.el8_10.x86_64.rpm SHA-256: c6fbb9cbf7f8853e219a61c8103de939f35f8a9ac7434d8b531b360ba4685192 Red Hat CodeReady Linux Builder for Power, little endian 8 SRPM ppc64le freerdp-debuginfo-2.11.7-7.el8_10.ppc64le.rpm SHA-256: 513bf6ed12b441cd5ee3f0f09d17bb5c92a06fc2a092dadae064cd51d0f9839f freerdp-debugsource-2.11.7-7.el8_10.ppc64le.rpm SHA-256: 9e236d516f494afc0dc7e0fbb49d57493a63c210bfd5b29f30abae77c7766190 freerdp-devel-2.11.7-7.el8_10.ppc64le.rpm SHA-256: 17e64fb89a00a15d0be0635b518e0431a5bd477de5241e66a4a26120cdad5f0b freerdp-libs-debuginfo-2.11.7-7.el8_10.ppc64le.rpm SHA-256: 73c9e6f5c46c3c4645ca8c1fdbccf86a3e14a99ce2e13e6d675a3b7d7f203980 libwinpr-debuginfo-2.11.7-7.el8_10.ppc64le.rpm SHA-256: b4f080667964dec2e1c7e9ee79b709a15536260de869b357896c616d1ae59eab Red Hat CodeReady Linux Builder for ARM 64 8 SRPM aarch64 freerdp-debuginfo-2.11.7-7.el8_10.aarch64.rpm SHA-256: b40777dbb8d25e3cbb3363f67938b152cbd089a
A critical heap buffer overflow (CVE-2026-33984, CVSS 7.5) in FreeRDP allows arbitrary code execution via crafted pixel data, while a separate flaw (CVE-2026-33983, CVSS 6.5) enables denial of service via specially crafted RDP messages. These vulnerabilities affect FreeRDP versions prior to 3.24.2. The fix requires upgrading FreeRDP to version 3.24.2.