FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the ClearCodec bands decode path when crafted band coordinates allow writes past the end of the destination surface buffer. A malicious server can trigger a client‑side heap buffer overflow, causing a crash (DoS) and potential heap corruption with code‑execution risk depending on allocator behavior and surrounding heap layout. Version 3.21.0 contains a patch for the issue.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:2048 https://access.redhat.com/errata/RHSA-2026:2048
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:2081 https://access.redhat.com/errata/RHSA-2026:2081
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:2222 https://access.redhat.com/errata/RHSA-2026:2222
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:2736 https://access.redhat.com/errata/RHSA-2026:2736
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:2952 https://access.redhat.com/errata/RHSA-2026:2952
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:3037 https://access.redhat.com/errata/RHSA-2026:3037