Fedora Account System
Red Hat Associate
Red Hat Customer
FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP files with /rdp2tcp, /cert:ignore, or /drive options to execute arbitrary commands, bypass certificate validation, or expose local filesystems without user interaction.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:54486 https://access.redhat.com/errata/RHSA-2026:54486
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:54485 https://access.redhat.com/errata/RHSA-2026:54485
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:54487 https://access.redhat.com/errata/RHSA-2026:54487
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:58711 https://access.redhat.com/errata/RHSA-2026:58711
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:58712 https://access.redhat.com/errata/RHSA-2026:58712
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:58710 https://access.redhat.com/errata/RHSA-2026:58710
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:58713 https://access.redhat.com/errata/RHSA-2026:58713
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:60173 https://access.redhat.com/errata/RHSA-2026:60173
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:61250 https://access.redhat.com/errata/RHSA-2026:61250
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:61251 https://access.redhat.com/errata/RHSA-2026:61251
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:62401 https://access.redhat.com/errata/RHSA-2026:62401