Opened 7 months ago

Closed 7 months ago

#22870 closed enhancement (fixed)

FreeRDP-3.23.0

Reported by: Bruce Dubbs Owned by: Douglas R. Reno
Priority: high Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New minor version.

Change History (4)

comment:1 by Douglas R. Reno, 7 months ago

Owner: changed from blfs-book to Douglas R. Reno
Status: new → assigned

comment:2 by Douglas R. Reno, 7 months ago

Priority: normal → elevated

comment:3 by Douglas R. Reno, 7 months ago

Priority: elevated → high
2026-02-25 Version 3.23.0

A new release and again a lot of changes:

    We’ve received in depth analysis of FreeRDP client code and have addressed shortcomings uncovered by these. 
CVE-2026-26965 CVE-2026-26955 CVE-2026-26271 CVE-2026-25997 
CVE-2026-25959 CVE-2026-25955 CVE-2026-25954 CVE-2026-25953 
CVE-2026-25952 CVE-2026-25942 CVE-2026-25941

Another weakness was reported, see https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-qcfc-ghxr-h927

    Configuration isolation was added. 3rd party client/server applications should check 
the new API freerdp_setApplicationDetails and winpr_setApplicationDetails which allows 
using a custom namespace for configuration files and runtime data per application
    For developers, we’ve marked most of the API with [[nodiscard]] now so compilers 
might start complaining about unchecked return values now. This is intentional and 
should give some incentive to clean up code. Functions where the return is optional have 
been omitted. For the time being these checks are automatically applied for FreeRDP 
builds, external projects can opt in by defining WINPR_DEFINE_ATTR_NODISCARD in their 
build system.
    For developers: Please start testing your applications against FreeRDP builds with
    -DWITHOUT_FREERDP_3x_DEPRECATED=ON
    to ensure you’re not using some soon to be removed API.
    SDL client did get a huge update, multimonitor and high DPI modes are now much 
improved
    We got a contribution for smartcard channel adding support for new attributes, so 
more applications might work now.

CVE fixes here include...

  • CVE-2026-25997 (Medium, heap use-after-free when comparing clipboard contents in the clipboard redirection code, PoC available)
  • CVE-2026-25959 (Medium, heap use-after-free in clipboard redirection code, PoC available)
  • CVE-2026-25955 (Medium, use-after-free while updating the display, PoC available)
  • CVE-2026-25954 (Medium, crash due to a null pointer dereference while resizing a window, PoC available)
  • CVE-2026-25953 (Medium, crash due to a pointer issue while resizing a window, PoC available)
  • CVE-2026-25952 (Medium, crash due to a pointer issue while determining the minimum and maximum sizes of a window, PoC available)
  • CVE-2026-25942 (Medium, remotely exploitable crash when a server sends an execResult value of 7 or greater, PoC available)
  • CVE-2026-25941 (High, remotely exploitable information disclosure and crash due to an out-of-bounds read while displaying bitmaps from a remote server, PoC available)
  • CVE-2026-27951 (Medium, crash due to an integer overflow on 32-bit systems when running Stream_EnsureCapacity)
  • CVE-2026-26965 (High, remotely exploitable out-of-bounds write that can lead to RCE and information disclosure)
  • CVE-2026-26955 (High, remotely exploitable heap buffer overflow that can lead to RCE and information disclosure)
  • CVE-2026-26271 (Medium, remotely exploitable crash when a FreeRDP icon is read)
Last edited 7 months ago by Douglas R. Reno (previous) (diff)

comment:4 by Douglas R. Reno, 7 months ago

Resolution: → fixed
Status: assigned → closed
Note: See TracTickets for help on using tickets.