SB20260930112 - Red Hat Enterprise Linux 10 update for freerdp
Published: September 30, 2026 Updated: September 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper handling of exceptional conditions (CVE-ID: CVE-2026-91949)
CWE-ID: CWE-755 - Improper Handling of Exceptional Conditions
CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass the configured transport security policy and disclose sensitive information.
The vulnerability exists due to improper handling of exceptional conditions in rdp_server_accept_nego() and protocol selection logic when processing an RDP negotiation failure followed by continued connection handling. A remote attacker can send an incompatible negotiation request and then continue the same connection to enter unintended RDSTLS processing to bypass the configured transport security policy and disclose sensitive information.
The issue is pre-authentication and can expose RDSTLS capabilities and related server-side parsers before the configured authentication mechanism runs.
Remediation
Install update from vendor's website.