- What: Security update for FreeRDP
- Impact: Addresses vulnerabilities in remote desktop protocol implementation
Red Hat Product Errata RHSA-2026:16483 - Security Advisory Issued: 2026-05-12 Updated: 2026-05-12 RHSA-2026:16483 - Security Advisory Overview Updated Packages Synopsis Moderate: freerdp security update Type/Severity Security Advisory: Moderate Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for freerdp is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox. Security Fix(es): freerdp: FreeRDP: Denial of service due to use-after-free vulnerability (CVE-2026-25952) freerdp: FreeRDP: Denial of Service via double free vulnerability during disconnect (CVE-2026-26986) freerdp: FreeRDP: Denial of Service via endless blocking loop in Stream_EnsureCapacity (CVE-2026-27951) freerdp: FreeRDP has a heap-buffer-overflow in bitmap_cache_put via OOB cacheId (CVE-2026-29775) freerdp: FreeRDP has an out-of-bounds read in ADPCM decoders due to missing predictor/step_index bounds checks (CVE-2026-31885) freerdp: FreeRDP has a division-by-zero in ADPCM decoders when `nBlockAlign` is 0 (CVE-2026-31884) freerdp: FreeRDP: Denial of Service via crafted audio data in RDP (CVE-2026-31883) FreeRDP: FreeRDP: Information disclosure via heap memory out of bounds read (CVE-2026-33985) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - AUS 9.2 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.2 s390x Fixes BZ - 2442768 - CVE-2026-25952 freerdp: FreeRDP: Denial of service due to use-after-free vulnerability BZ - 2442782 - CVE-2026-26986 freerdp: FreeRDP: Denial of Service via double free vulnerability during disconnect BZ - 2442783 - CVE-2026-27951 freerdp: FreeRDP: Denial of Service via endless blocking loop in Stream_EnsureCapacity BZ - 2447379 - CVE-2026-29775 freerdp: FreeRDP has a heap-buffer-overflow in bitmap_cache_put via OOB cacheId BZ - 2447383 - CVE-2026-31885 freerdp: FreeRDP has an out-of-bounds read in ADPCM decoders due to missing predictor/step_index bounds checks BZ - 2447385 - CVE-2026-31884 freerdp: FreeRDP has a division-by-zero in ADPCM decoders when `nBlockAlign` is 0 BZ - 2447386 - CVE-2026-31883 freerdp: FreeRDP: Denial of Service via crafted audio data in RDP BZ - 2453217 - CVE-2026-33985 FreeRDP: FreeRDP: Information disclosure via heap memory out of bounds read CVEs CVE-2026-25952 CVE-2026-26986 CVE-2026-27951 CVE-2026-29775 CVE-2026-31883 CVE-2026-31884 CVE-2026-31885 CVE-2026-33985 References https://access.redhat.com/security/updates/classification/#moderate Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - AUS 9.2 SRPM freerdp-2.4.1-6.el9_2.9.src.rpm SHA-256: 3c23efec6069a8e9d40b6d37ec8c0d76331e68c37e10d6b74da5d9ab652f6f79 x86_64 freerdp-2.4.1-6.el9_2.9.x86_64.rpm SHA-256: 1867716e0365a39889b465aa225a46fd197fd6fac382100489416a13a43a351e freerdp-debuginfo-2.4.1-6.el9_2.9.i686.rpm SHA-256: 29d9b1ac4ce1c50e9688632ba9e262b1063744579c55cddec8a66efa11a26bd0 freerdp-debuginfo-2.4.1-6.el9_2.9.x86_64.rpm SHA-256: 54010efb1793dd32ba9b00d23bebdf20f910291c267b6f1ee338aec296ffbd7b freerdp-debugsource-2.4.1-6.el9_2.9.i686.rpm SHA-256: deb951f60884f4953b74f3e5b93080b2a3b2e4d08014206465caadfb9f4d4395 freerdp-debugsource-2.4.1-6.el9_2.9.x86_64.rpm SHA-256: 62bf537377026b175f8dc71a3354ec95f21e062e44c00108204a2d03f05cf7c5 freerdp-libs-2.4.1-6.el9_2.9.i686.rpm SHA-256: 98864a622a128ffb58ed6ce546d20f211f7ff64cdd9c5f0f06912095b9308dde freerdp-libs-2.4.1-6.el9_2.9.x86_64.rpm SHA-256: 5819f71f10c04af05b67ae2f3cdccbc67331cbdbf0c7c9adca0fac83842cc5f3 freerdp-libs-debuginfo-2.4.1-6.el9_2.9.i686.rpm SHA-256: c8d57b4a6dcdb24d7c40d567387adacb3413146dc82b0a2f944e4a007a7eef7d freerdp-libs-debuginfo-2.4.1-6.el9_2.9.x86_64.rpm SHA-256: 31928f42fd8c46f38943a7632102434e8b0e83a12c5b4db953ae99e49dcc6f6a libwinpr-2.4.1-6.el9_2.9.i686.rpm SHA-256: d16a2910f41052930afe34efb4437c769b5289793b7a84210601743e8124afb8 libwinpr-2.4.1-6.el9_2.9.x86_64.rpm SHA-256: d84f5a92c790f2b815e169d1bc90f466f5f90195e9a5d587beac1e513bd19296 libwinpr-debuginfo-2.4.1-6.el9_2.9.i686.rpm SHA-256: d5c5da8c781d228457013863c9157aa62c0f3ef025e9efbb7b2f7cc7cb1a9794 libwinpr-debuginfo-2.4.1-6.el9_2.9.x86_64.rpm SHA-256: 54831352d2304fe37de6862ffe031911a85ab694c937f56b4ddb384116eb26fd Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 SRPM freerdp-2.4.1-6.el9_2.9.src.rpm SHA-256: 3c23efec6069a8e9d40b6d37ec8c0d76331e68c37e10d6b74da5d9ab652f6f79 ppc64le freerdp-2.4.1-6.el9_2.9.ppc64le.rpm SHA-256: b95012668734827dc55383ed892e242209bb69ff2fbc9b65a256f47f507b3aa2 freerdp-debuginfo-2.4.1-6.el9_2.9.ppc64le.rpm SHA-256: c04253e3be62aca18c9f7ceccb68f1a67ccd737e5defe3518d7e48f1152115df freerdp-debugsource-2.4.1-6.el9_2.9.ppc64le.rpm SHA-256: 8a03c918ba87d0a5ad0af18f87e0b3728c2fde7f8dad53da2bd0df05706ccf1f freerdp-libs-2.4.1-6.el9_2.9.ppc64le.rpm SHA-256: 0a0599736320defd79723b73dd2cebdcf06c17a8dbcc174dc5d9c312ce7fdc4d freerdp-libs-debuginfo-2.4.1-6.el9_2.9.ppc64le.rpm SHA-256: 2aed5ed1bf534b69f19c3d217e7c28abb32f9de9a749d22943a37608f753dc56 libwinpr-2.4.1-6.el9_2.9.ppc64le.rpm SHA-256: 29a08b4df1487b2cf02ef9d203776ea09e091e6b76058942314959be558ca8d3 libwinpr-debuginfo-2.4.1-6.el9_2.9.ppc64le.rpm SHA-256: d55606828f8c390052ec58690cae4417d9f4f4d4ff79253442b788c67ceee23d Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 SRPM freerdp-2.4.1-6.el9_2.9.src.rpm SHA-256: 3c23efec6069a8e9d40b6d37ec8c0d76331e68c37e10d6b74da5d9ab652f6f79 x86_64 freerdp-2.4.1-6.el9_2.9.x86_64.rpm SHA-256: 1867716e0365a39889b465aa225a46fd197fd6fac382100489416a13a43a351e freerdp-debuginfo-2.4.1-6.el9_2.9.i686.rpm SHA-256: 29d9b1ac4ce1c50e9688632ba9e262b1063744579c55cddec8a66efa11a26bd0 freerdp-debuginfo-2.4.1-6.el9_2.9.x86_64.rpm SHA-256: 54010efb1793dd32ba9b00d23bebdf20f910291c267b6f1ee338aec296ffbd7b freerdp-debugsource-2.4.1-6.el9_2.9.i686.rpm SHA-256: deb951f60884f4953b74f3e5b93080b2a3b2e4d08014206465caadfb9f4d4395 freerdp-debugsource-2.4.1-6.el9_2.9.x86_64.rpm SHA-256: 62bf537377026b175f8dc71a3354ec95f21e062e44c00108204a2d03f05cf7c5 freerdp-libs-2.4.1-6.el9_2.9.i686.rpm SHA-256: 98864a622a128ffb58ed6ce546d20f211f7ff64cdd9c5f0f06912095b9308dde freerdp-libs-2.4.1-6.el9_2.9.x86_64.rpm SHA-256: 5819f71f10c04af05b67ae2f3cdccbc67331cbdbf0c7c9adca0fac83842cc5f3 freerdp-libs-debuginfo-2.4.1-6.el9_2.9.i686.rpm SHA-256: c8d57b4a6dcdb24d7c40d567387adacb3413146dc82b0a2f944e4a007a7eef7d freerdp-libs-debuginfo-2.4.1-6.el9_2.9.x86_64.rpm SHA-256: 31928f42fd8c46f38943a7632102434e8b0e83a12c5b4db953ae99e49dcc6f6a libwinpr-2.4.1-6.el9_2.9.i686.rpm SHA-256: d16a2910f41052930afe34efb4437c769b5289793b7a84210601743e8124afb8 libwinpr-2.4.1-6.el9_2.9.x86_64.rpm SHA-256: d84f5a92c790f2b815e169d1bc90f466f5f90195e9a5d587beac1e513bd19296 libwinpr-debuginfo-2.4.1-6.el9_2.9.i686.rpm SHA-256: d5c5da8c781d228457013863c9157aa62c0f3ef025e9efbb7b2f7cc7cb1a9794 libwinpr-debuginfo-2.4.1-6.el9_2.9.x86_64.rpm SHA-256: 54831352d2304fe37de6862ffe031911a85ab694c937f56b4ddb384116eb26fd Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 SRPM freerdp-2.4.1-6.el9_2.9.src.rpm SHA-256: 3c23efec6069a8e9d40b6d37ec8c0d76331e68c37e10d6b74da5d9ab652f6f79 aarch64 freerdp-2.4.1-6.el9_2.9.aarch64.rpm SHA-256: 2a5a9d1f7884b28fd721d379e9d7af1f4541a8e837ba2065ec0679f4cd9c2265 freerdp-debuginfo-2.4.1-6.el9_2.9.aarch64.rpm SHA-256: 7298e85151a2c83d490c36c2bdf39b05637b96f1edfce491499017bcf84310a3 freerdp-debugsource-2.4.1-6.el9_2.9.aarch64.rpm SHA-256: 0a5e7fe1cbe3ebdbac764eac6ea33e8f97a454d0594e5de13640e6f8a778d70d freerdp-libs-2.4.1-6.el9_2.9.aarch64.rpm SHA-256: fa3d6311cc016392770aa34fa396ff594a10f25f9a277121e7410011f91bf571 freerdp-libs-debuginfo-2.4.1-6.el9_2.9.aarch64.rpm SHA-256: 40ff22a271c5cd479688a611af402d6755c632dd9b47516ca2a58819aa587326 libwinpr-2.4.1-6.el9_2.9.aarch64.rpm SHA-256: 7684843d82a96b89c670cd30ed11c84ecc25d48279c4d584c174aaf432fe88c1 libwinpr-debuginfo-2.4.1-6.el9_2.9.aarch64.rpm SHA-256: 1f29ef9264cc7e7feab9d544b899bb2cf96c9b75f8a9b2376275f97bc0e26533 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 SRPM freerdp-2.4.1-6.el9_2.9.src.rpm SHA-256: 3c23efec6069a8e9d40b6d37ec8c0d76331e68c37e10d6b74da5d9ab652f6f79 s390x freerdp-2.4.1-6.el9_2.9.s390x.rpm SHA-256: 934c6740753b5b3199d179217e5edcf476fa886ea5233e2f416023a2ae91d80b freerdp-debuginfo-2.4.1-6.el9_2.9.s390x.rpm SHA-256: 3a4cd546dd106b66b7e823b5ea4c8af0545926778d0e8ff8255a9cd449d51961 freerdp-debugsource-2.4.1-6.el9_2.9.s390x.rpm SHA-256: d137a4de9672094102ac697f81fd645c75400139460db44b2153ea62099630f7 freerdp-libs-2.4.1-6.el9_2.9.s390x.rpm SHA