Opened 7 months ago

Closed 7 months ago

#22976 closed enhancement (fixed)

FreeRDP-3.24.0 (Security update)

Reported by: Bruce Dubbs Owned by: zeckma
Priority: high Milestone: 13.1
Component: BOOK Version: git
Severity: critical Keywords:
Cc:

Description

New minor version.

Change History (8)

comment:1 by Bruce Dubbs, 7 months ago

Owner: changed from blfs-book to Bruce Dubbs
Status: new → assigned

comment:2 by Bruce Dubbs, 7 months ago

Priority: normal → elevated
Summary: FreeRDP-3.24.0 → FreeRDP-3.24.0 (Security update)

# 2026-03-13 Version 3.24.0

A new release with bugfixes and many improvements for users and developers alike.

  • Completed the [[nodiscard]] marking of the API to warn about problematic unchecked use of functions
  • Added full C23 support (default stays at C11) to allow new compilers to do stricter checking
  • Improved X11 and SDL3 clients
  • Improved smartcard support
  • proxy now supports RFX graphics mode

## Security Advisories

  • CVE-2026-29774
  • CVE-2026-29775
  • CVE-2026-29776
  • CVE-2026-31806
  • CVE-2026-31883
  • CVE-2026-31884
  • CVE-2026-31885
  • CVE-2026-31897

# What's Changed

  • Attribute nodiscard related chanes
  • c23 related improvements
  • Generic code cleanups
  • [core,utils] ignore NULL values in remove_rdpdr_type
  • [core,gateway] ignore incomplete rpc header
  • [warnings] make function declaration names consistent
  • [libfreerdp] Add new define for logon error info
  • [client,x11] improve rails window locking
  • Reload fix missing null checks
  • Bounds checks
  • [server,proxy] check for nullptr before using scard_call_context
  • [uwac] fix rectangular glitch around surface damage regions
  • Address various error handling inconsistencies
  • [core,server] Improve WTS API locking
  • Address some GCC compile issues
  • Winpr atexit
  • [winpr,smartcard] fix function pointer casts
  • Xf timer fix
  • [client,sdl] workaround for wlroots compositors
  • [client,sdl] fix SdlWindow::query
  • [winpr,smartcard] fix PCSC_ReleaseCardContext
  • [client,x11] eliminate obsolete compile flags
  • [client,common] skip sending input events when not connected
  • Input connected checks
  • Floatbar and display channel improvements
  • [winpr,platform] fix WINPR_ATTR_NODISCARD definition
  • [client] Fix writing of gatewayusagemethod to .rdp files
  • Nodiscard finetune
  • [core] fix missing gateway credential sync
  • [client,sdl3] limit FREERDP_WLROOTS_HACK
  • [core,settings] Allow FreeRDP_instance in setter
  • [codec,h264] make log message trace
  • X11 rails improve
  • [codec,nsc] limit copy area in nsc_process_message
  • Proxy support RFX and NSC settings
  • [client,common] display a shortened help on parsing issues
  • [winpr,smartcard] refine locking for pcsc layer
  • [codec,swscale] allow runtime loading of swscale
  • Swscale fallback
  • Sdl multi scaling support
  • [packaging,flatpak] update runtime and dependencies
  • [codec,video] add doxygen version details
  • [github,templates] update templates
  • [client,sdl] allow FREERDP_WLROOTS_HACK for all sessions
  • [warnings,nodiscard] add log messages for failures
  • [gdi,gdi] ignore empty rectangles
  • Smartcard fix smartcard-login, pass rdpContext for abort
  • [winpr,smartcard] fix compiler warnings
  • [winpr,timezone] fix search for transition dates
  • [client,common] improve /p help
  • Scard logging refactored
  • [emu,scard] fix smartcard emulation
  • Sdl null cursor

comment:3 by Bruce Dubbs, 7 months ago

Fixed at commit 17bdb8dcf2.

Leaving open for security advisory.

comment:4 by Bruce Dubbs, 7 months ago

Owner: changed from Bruce Dubbs to zeckma
Status: assigned → new

comment:5 by zeckma, 7 months ago

Status: new → assigned

comment:6 by zeckma, 7 months ago

Priority: elevated → high
Severity: normal → critical

comment:7 by zeckma, 7 months ago

Security fixes (Critical)

  • CVE-2026-29774 (High): Heap buffer overflow
  • CVE-2026-29775 (High): Heap out-of-bounds read and write
  • CVE-2026-29776 (Low): Integer underflow
  • CVE-2026-31806 (Critical): Heap buffer overflow (allows heap memory overwrite)
  • CVE-2026-31883 (Critical): Integer underflow leads to Heap buffer overflow (long while loop time)
  • CVE-2026-31884 (High): Division by zero (denial of service)
  • CVE-2026-31885 (Critical): Out of bounds read
  • CVE-2026-31897 (Critical): Out of bounds read
Last edited 7 months ago by zeckma (previous) (diff)

comment:8 by zeckma, 7 months ago

Resolution: → fixed
Status: assigned → closed

SA-13.0-012 issued.

Note: See TracTickets for help on using tickets.