SB2026100141 - Red Hat Enterprise Linux 10 update for freerdp



SB2026100141 - Red Hat Enterprise Linux 10 update for freerdp

Published: October 1, 2026 Updated: October 1, 2026

Security Bulletin ID SB2026100141
CSH Severity
High
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Heap-based buffer overflow (CVE-ID: CVE-2026-55193)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to heap-based buffer overflow in the TS Gateway RPC fragment receive logic when processing RESPONSE fragments from a TS Gateway after RPC bind negotiation. A remote attacker can send a crafted bind_ack and subsequent oversized RESPONSE fragments to execute arbitrary code.

The issue affects FreeRDP clients using TS Gateway / RD Gateway transport, and can also be triggered by an active machine-in-the-middle on gateway traffic. Direct RDP connections that do not use the gateway RPC layer are not affected.


2) Improper handling of exceptional conditions (CVE-ID: CVE-2026-91949)

CWE-ID: CWE-755 - Improper Handling of Exceptional Conditions

CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass the configured transport security policy and disclose sensitive information.

The vulnerability exists due to improper handling of exceptional conditions in rdp_server_accept_nego() and protocol selection logic when processing an RDP negotiation failure followed by continued connection handling. A remote attacker can send an incompatible negotiation request and then continue the same connection to enter unintended RDSTLS processing to bypass the configured transport security policy and disclose sensitive information.

The issue is pre-authentication and can expose RDSTLS capabilities and related server-side parsers before the configured authentication mechanism runs.


Remediation

Install update from vendor's website.