Red Hat Product Errata RHSA-2026:11336 - Security Advisory Issued: 2026-04-28 Updated: 2026-04-28 RHSA-2026:11336 - Security Advisory Overview Updated Packages Synopsis Important: freerdp security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for freerdp is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox. Security Fix(es): FreeRDP: FreeRDP: Heap buffer overflow allows arbitrary code execution via crafted pixel data (CVE-2026-33984) FreeRDP: FreeRDP: Denial of Service via specially crafted Remote Desktop Protocol messages (CVE-2026-33983) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - AUS 9.2 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.2 s390x Fixes BZ - 2453219 - CVE-2026-33984 FreeRDP: FreeRDP: Heap buffer overflow allows arbitrary code execution via crafted pixel data BZ - 2453220 - CVE-2026-33983 FreeRDP: FreeRDP: Denial of Service via specially crafted Remote Desktop Protocol messages CVEs CVE-2026-33983 CVE-2026-33984 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - AUS 9.2 SRPM freerdp-2.4.1-6.el9_2.7.src.rpm SHA-256: ef49cfcae2f918026bc61b48acb4e419ce5ea38ce6d1622fd62c58c1074366a0 x86_64 freerdp-2.4.1-6.el9_2.7.x86_64.rpm SHA-256: c26f2cff070def2411dd0f064db8aa9e7f79f7fc430c098123e1b6ffeb9d8182 freerdp-debuginfo-2.4.1-6.el9_2.7.i686.rpm SHA-256: 45518487d17db3a0c0b478fbfa441ccf3454c50a6207d8cb75d70c762b63632f freerdp-debuginfo-2.4.1-6.el9_2.7.x86_64.rpm SHA-256: b2ca3f02577cf95f1c885830b4f158d2f367329c1f838d25600c32227f379991 freerdp-debugsource-2.4.1-6.el9_2.7.i686.rpm SHA-256: b528c3a7df8775e7a942f58c2da2f4052be0c44c85f5c055885d683251e77ed8 freerdp-debugsource-2.4.1-6.el9_2.7.x86_64.rpm SHA-256: 127f62577aaeba49694f9426ec0d6c4d115526c0573a64632625bd836122e8d4 freerdp-libs-2.4.1-6.el9_2.7.i686.rpm SHA-256: 1d274aef6aca87af0a6b23a4e7790f68daa0f66e00f91475292f892634244446 freerdp-libs-2.4.1-6.el9_2.7.x86_64.rpm SHA-256: 32ea4b353b275d48e8f72c41a5f3f5a4b8bc3de08a2d50d17500b816bac42536 freerdp-libs-debuginfo-2.4.1-6.el9_2.7.i686.rpm SHA-256: 99d35dbd61f68590bd6ba2e67a28d8468e4f062207dfd2304f9669743d903168 freerdp-libs-debuginfo-2.4.1-6.el9_2.7.x86_64.rpm SHA-256: 1d55c7745b022cb5157f0491ccf2bbf143c088247b191c64162915df3ba58fb0 libwinpr-2.4.1-6.el9_2.7.i686.rpm SHA-256: f8ad6226c48b3f4f7df0aeba6fd137172052c206f84c07de15928fca848d5889 libwinpr-2.4.1-6.el9_2.7.x86_64.rpm SHA-256: 187373a04e64d0321af0fff852bfdbb406563caabc5c6f302f892d8449a8d305 libwinpr-debuginfo-2.4.1-6.el9_2.7.i686.rpm SHA-256: 257b1090cf5bb4adfe64c30aa62185e3a108b8bf4eb0c1efb94701bef593ac90 libwinpr-debuginfo-2.4.1-6.el9_2.7.x86_64.rpm SHA-256: 6dffe46f414c9d24269f774f466b6e03be492d4994ffa2d2f8e178f2d170ef73 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 SRPM freerdp-2.4.1-6.el9_2.7.src.rpm SHA-256: ef49cfcae2f918026bc61b48acb4e419ce5ea38ce6d1622fd62c58c1074366a0 ppc64le freerdp-2.4.1-6.el9_2.7.ppc64le.rpm SHA-256: 6bf25431ea8b6533b41866d300749a9fda80000da1a55d3e8e1f6e5f642caf48 freerdp-debuginfo-2.4.1-6.el9_2.7.ppc64le.rpm SHA-256: 4803338afddacf782bc2a5833193923456dfc16a663698c89e6f1db1a6c57e9d freerdp-debugsource-2.4.1-6.el9_2.7.ppc64le.rpm SHA-256: 804d4548391e3d6e01393313c78b8c93315c6fc57757fc157c4d1ad0854e83b9 freerdp-libs-2.4.1-6.el9_2.7.ppc64le.rpm SHA-256: ddc4fe2b0282125c1c455cee3476502edd2a013ba9c0c3eb5f2ca337eb3e8420 freerdp-libs-debuginfo-2.4.1-6.el9_2.7.ppc64le.rpm SHA-256: b1b0db5e08fdc0b52ac1e5e6995272d119db15c6c29cb2013166a605cf5799bf libwinpr-2.4.1-6.el9_2.7.ppc64le.rpm SHA-256: 027811557e732a83e30cbd071e4ee91b36371f9ef004c4247d214adfbcfa2322 libwinpr-debuginfo-2.4.1-6.el9_2.7.ppc64le.rpm SHA-256: d06cdce197f971e0e4eb51281899ab72baac89d30926eb64794e5001f777b09d Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 SRPM freerdp-2.4.1-6.el9_2.7.src.rpm SHA-256: ef49cfcae2f918026bc61b48acb4e419ce5ea38ce6d1622fd62c58c1074366a0 x86_64 freerdp-2.4.1-6.el9_2.7.x86_64.rpm SHA-256: c26f2cff070def2411dd0f064db8aa9e7f79f7fc430c098123e1b6ffeb9d8182 freerdp-debuginfo-2.4.1-6.el9_2.7.i686.rpm SHA-256: 45518487d17db3a0c0b478fbfa441ccf3454c50a6207d8cb75d70c762b63632f freerdp-debuginfo-2.4.1-6.el9_2.7.x86_64.rpm SHA-256: b2ca3f02577cf95f1c885830b4f158d2f367329c1f838d25600c32227f379991 freerdp-debugsource-2.4.1-6.el9_2.7.i686.rpm SHA-256: b528c3a7df8775e7a942f58c2da2f4052be0c44c85f5c055885d683251e77ed8 freerdp-debugsource-2.4.1-6.el9_2.7.x86_64.rpm SHA-256: 127f62577aaeba49694f9426ec0d6c4d115526c0573a64632625bd836122e8d4 freerdp-libs-2.4.1-6.el9_2.7.i686.rpm SHA-256: 1d274aef6aca87af0a6b23a4e7790f68daa0f66e00f91475292f892634244446 freerdp-libs-2.4.1-6.el9_2.7.x86_64.rpm SHA-256: 32ea4b353b275d48e8f72c41a5f3f5a4b8bc3de08a2d50d17500b816bac42536 freerdp-libs-debuginfo-2.4.1-6.el9_2.7.i686.rpm SHA-256: 99d35dbd61f68590bd6ba2e67a28d8468e4f062207dfd2304f9669743d903168 freerdp-libs-debuginfo-2.4.1-6.el9_2.7.x86_64.rpm SHA-256: 1d55c7745b022cb5157f0491ccf2bbf143c088247b191c64162915df3ba58fb0 libwinpr-2.4.1-6.el9_2.7.i686.rpm SHA-256: f8ad6226c48b3f4f7df0aeba6fd137172052c206f84c07de15928fca848d5889 libwinpr-2.4.1-6.el9_2.7.x86_64.rpm SHA-256: 187373a04e64d0321af0fff852bfdbb406563caabc5c6f302f892d8449a8d305 libwinpr-debuginfo-2.4.1-6.el9_2.7.i686.rpm SHA-256: 257b1090cf5bb4adfe64c30aa62185e3a108b8bf4eb0c1efb94701bef593ac90 libwinpr-debuginfo-2.4.1-6.el9_2.7.x86_64.rpm SHA-256: 6dffe46f414c9d24269f774f466b6e03be492d4994ffa2d2f8e178f2d170ef73 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 SRPM freerdp-2.4.1-6.el9_2.7.src.rpm SHA-256: ef49cfcae2f918026bc61b48acb4e419ce5ea38ce6d1622fd62c58c1074366a0 aarch64 freerdp-2.4.1-6.el9_2.7.aarch64.rpm SHA-256: a36e42061b1cbfab1f27e00d1842ea2d036d224eec104bb0058dd6d318631d43 freerdp-debuginfo-2.4.1-6.el9_2.7.aarch64.rpm SHA-256: 5ed9209a4719ddfa46fcfd2c0e575a16e925982a882d4f91927e8ab1831ff9cb freerdp-debugsource-2.4.1-6.el9_2.7.aarch64.rpm SHA-256: 5fffb43b52ec736202f1fb01d8ae8e800b24aaf2123ef75ebbf50f11d80f631b freerdp-libs-2.4.1-6.el9_2.7.aarch64.rpm SHA-256: 1348ffe15beb1025972de837c8156a5c6e139f6cbdd08dd7e7e33b53c5a5d990 freerdp-libs-debuginfo-2.4.1-6.el9_2.7.aarch64.rpm SHA-256: 138d3d2187329308000693fec61b2996662ea29b90000f09e5da1955021758d8 libwinpr-2.4.1-6.el9_2.7.aarch64.rpm SHA-256: 7bd1d20ab53a76652edeb00ff24f1c7f7e7194798ef023eeaea4a93f9282aa3e libwinpr-debuginfo-2.4.1-6.el9_2.7.aarch64.rpm SHA-256: 0a0199d780769c62f56143e35c478f5fe2061619b7266fb27943f919cc77b022 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 SRPM freerdp-2.4.1-6.el9_2.7.src.rpm SHA-256: ef49cfcae2f918026bc61b48acb4e419ce5ea38ce6d1622fd62c58c1074366a0 s390x freerdp-2.4.1-6.el9_2.7.s390x.rpm SHA-256: e8b0450d6f982e60ac37474f4283fb15f3a0a8b2e4730644a18e7e23dc41a391 freerdp-debuginfo-2.4.1-6.el9_2.7.s390x.rpm SHA-256: dffeeef56a50d9ff3ddec0ebff795d6a2ef1727b0572f5e0bf567e4b3170799d freerdp-debugsource-2.4.1-6.el9_2.7.s390x.rpm SHA-256: 971f45dce5c570974b3296027ce29645ea484c4da4df56580efc8bb8d4ce3964 freerdp-libs-2.4.1-6.el9_2.7.s390x.rpm SHA-256: d22930a25f1737edc32d207a5991b9670926fcf92b3748afa6e96602ac27a496 freerdp-libs-debuginfo-2.4.1-6.el9_2.7.s390x.rpm SHA-256: a419c94516122cbd2cb5ef96982215efc790a8981864d6610e97c364fbd9f929 libwinpr-2.4.1-6.el9_2.7.s390x.rpm SHA-256: eb6ecb8215f3da88aa88a7b010a94efd81426d467942097d86cdf7cd8c8b1998 libwinpr-debuginfo-2.4.1-6.el9_2.7.s390x.rpm SHA-256: 96ac1b53815498f6887916ea033233ece79a258cec696a320a17c09a2a09b1ea Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2 SRPM freerdp-2.4.1-6.el9_2.7.src.rpm SHA-256: ef49cfcae2f918026bc61b48acb4e419ce5ea38ce6d1622fd62c58c1074366a0 x86_64 freerdp-2.4.1-6.el9_2.7.x86_64.rpm SHA-256: c26f2cff070def2411dd0f064db8aa9e7f79f7fc430c098123e1b6ffeb9d8182 freerdp-debuginfo-2.4.1-6.el9_2.7.i686.rpm SHA-256: 45518487d17db3a0c0b478fbfa441ccf3454c50a6207d8cb75d70c762b63632f freerdp-debuginfo-2.4.1-6.el9_2.7.x86_64.rpm SHA-256: b2ca3f02577cf95f1c885830b4f158d2f367329c1f838d25600c32227f379991 freerdp-debugsource-2.4.1-6.el9_2.7.i686.rpm SHA-256: b528c3a7df8775e7a942f58c2da2f4052be0c44c85f5c055885d683251e77ed8 freerdp-debugsource-2.4.1-6.el9_2.7.x86_64.rpm SHA-256: 127f62577aaeba49694f9426ec0d6c4d115526c0573a64632625bd836122e8d4 freerdp-libs-2.4.1-6.el9_2.7.i686.rpm SHA-256: 1d274aef6aca87af0a6b23a4e7790f68daa0f66e00f91475292f892634244446 freerdp-libs-2.
A heap buffer overflow (CVE-2026-33984, CVSS 7.5 High) in FreeRDP allows arbitrary code execution via crafted pixel data, while a separate flaw (CVE-2026-33983, CVSS 6.5 Medium) enables denial of service via specially crafted RDP messages. These vulnerabilities affect FreeRDP versions prior to 3.24.2. The fix is to upgrade FreeRDP to version 3.24.2.