SB2026092196 - Red Hat Enterprise Linux 8 update for freerdp



SB2026092196 - Red Hat Enterprise Linux 8 update for freerdp

Published: September 21, 2026

Security Bulletin ID SB2026092196
CSH Severity
High
Patch available
YES
Number of vulnerabilities 4
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 25% Medium 75%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 4 vulnerabilities.


1) Out-of-bounds read (CVE-ID: CVE-2026-67301)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service or disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in the async update message proxy for PolygonSC orders when processing crafted primary drawing orders from a malicious RDP server with AsyncUpdate enabled. A remote attacker can send a specially crafted PolygonSC update order to cause a denial of service or disclose sensitive information.

The issue affects the client side and requires AsyncUpdate to be enabled.


2) Improper validation of certificate with host mismatch (CVE-ID: CVE-2026-67288)

CWE-ID: CWE-297 - Improper Validation of Certificate with Host Mismatch

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass tls server hostname validation.

The vulnerability exists due to improper certificate hostname validation in tls_match_hostname() when verifying wildcard tls certificates for multi-label hostnames. A remote attacker can present a crafted wildcard certificate to bypass tls server hostname validation.

This issue affects cases where a certificate for a single-label wildcard domain is incorrectly accepted for a hostname with multiple labels.


3) Out-of-bounds read (CVE-ID: CVE-2026-67291)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to out-of-bounds read in update_process_glyph_fragments() and glyph_cache_fragment_put() when processing GLYPH_FRAGMENT_ADD data from an RDP server. A remote attacker can send a short GLYPH_FRAGMENT_ADD payload with a larger declared fragment size to cause a denial of service.

The demonstrated impact is a client-side crash, and no attacker-controlled write primitive, remote code execution, or direct information disclosure beyond the out-of-bounds read was confirmed.


4) Heap-based buffer overflow (CVE-ID: CVE-2026-55194)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code or cause a denial of service.

The vulnerability exists due to heap-based buffer overflow in rpc_client_recv_fragment() in the TS Gateway RPC response reassembly logic when processing a crafted PTYPE_RESPONSE PDU on the RPC OUT channel after gateway negotiation. A remote attacker can send a specially crafted gateway response with a small alloc_hint and oversized stub data to execute arbitrary code or cause a denial of service.

Only FreeRDP clients using TS Gateway / RD Gateway transport are affected; direct RDP connections without the gateway RPC layer are not affected. In default builds the issue may abort via an assertion, while release builds without assertion enforcement may permit exploitation.


Remediation

Install update from vendor's website.