Fedora Account System
Red Hat Associate
Red Hat Customer
FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, receive negotiation failures, then complete TLS handshake and enter RDSTLS to bypass pre-authentication transport restrictions.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:73979 https://access.redhat.com/errata/RHSA-2026:73979
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:74471 https://access.redhat.com/errata/RHSA-2026:74471