Bug 2443132 (CVE-2026-26955)
| Summary: | CVE-2026-26955 freerdp: FreeRDP: Arbitrary code execution via heap buffer overflow in GDI surface pipeline | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in FreeRDP, a free implementation of the Remote Desktop Protocol (RDP). A malicious RDP server can exploit a heap buffer overflow vulnerability by sending a specially crafted graphics command to a FreeRDP client. This allows the server to write data outside of its intended memory region, potentially leading to arbitrary code execution on the client system. The vulnerability occurs because the client does not properly validate the dimensions of incoming graphics commands.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2443144, 2443146, 2443145 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-02-26 21:04:09 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:5936 https://access.redhat.com/errata/RHSA-2026:5936 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:5939 https://access.redhat.com/errata/RHSA-2026:5939 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:6005 https://access.redhat.com/errata/RHSA-2026:6005 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:6004 https://access.redhat.com/errata/RHSA-2026:6004 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:6384 https://access.redhat.com/errata/RHSA-2026:6384 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:6385 https://access.redhat.com/errata/RHSA-2026:6385 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2026:6395 https://access.redhat.com/errata/RHSA-2026:6395 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:6396 https://access.redhat.com/errata/RHSA-2026:6396 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:6616 https://access.redhat.com/errata/RHSA-2026:6616 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:6665 https://access.redhat.com/errata/RHSA-2026:6665 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2026:6712 https://access.redhat.com/errata/RHSA-2026:6712 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:6764 https://access.redhat.com/errata/RHSA-2026:6764 This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:7292 https://access.redhat.com/errata/RHSA-2026:7292 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:19033 https://access.redhat.com/errata/RHSA-2026:19033 |