Opened 5 months ago
Closed 4 months ago
#23257 closed enhancement (fixed)
FreeRDP-3.26.0
| Reported by: | Bruce Dubbs | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | high | Milestone: | 13.1 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New minor version.
Change History (5)
comment:1 by , 5 months ago
| Priority: | normal → high |
|---|
comment:2 by , 5 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:3 by , 5 months ago
| Owner: | changed from to |
|---|---|
| Status: | assigned → new |
Fixed at b502b0cd3c. Leaving open for SA.
comment:4 by , 4 months ago
- CVE-2026-44420 (8.8 High): FreeRDP cliprdr server heap-buffer-overflow via undersized capabilitySetLength in CB_CLIP_CAPS. RCE and DoS
- CVE-2026-45700 (8.8 High): Heap-buffer-overflow write in planar bitmap decoder. RCE and DoS
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-p6r2-4hgm-m6ff - "
FreeRDP RDPGFX CacheToSurface heap-buffer-overflow via clamped-rectangle validation bypass"... no CVE assigned, but 8.8 High rating assigned. DoS and possible RCE.
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-j9q5-7g8m-jc9v - "FreeRDP RDPEAR NDR ref-id aliasing causes client-side UAF/double-free and type confusion"... 7.5 High rating assigned, no CVE assigned. Type confusion causing possible RCE, but primary impact is DoS.
Note:
See TracTickets
for help on using tickets.

3.26.0
Mostly a bugfix and maintenance release with a few nice additions:
CVE fixes
What's Changed