SB20260408127 - openEuler update for freerdp
Published: April 8, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Integer underflow (CVE-ID: CVE-2026-29776)
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer underflow in update_read_cache_bitmap_order() in libfreerdp/core/orders.c when processing a crafted bitmap cache order from the network. A remote attacker can send a specially crafted RDP update that causes excessive memory allocation and process termination to cause a denial of service.
User interaction is required, and exploitation occurs in the client while handling server-supplied RDP data.
Remediation
Install update from vendor's website.