{"id":"RHSA-2026:54486","summary":"Red Hat Security Advisory: freerdp security update","modified":"2026-08-14T10:32:32.350583106Z","published":"2026-08-14T10:16:44Z","upstream":["CVE-2026-64620","CVE-2026-64621","CVE-2026-64624","CVE-2026-67289","CVE-2026-67299","CVE-2026-68580"],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:54486"},{"type":"ARTICLE","url":"https://access.redhat.com/security/updates/classification/#important"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2502752"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2502766"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2503096"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2509985"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2510004"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2510125"},{"type":"ADVISORY","url":"https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_54486.json"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-64620"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-64620"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64620"},{"type":"ARTICLE","url":"https://github.com/FreeRDP/FreeRDP/commit/1f7a716d39b5605bb8a83b0c3c97a6ce386609ef"},{"type":"ARTICLE","url":"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-pjqx-v446-x7fc"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/freerdp-before-heap-buffer-overflow-via-crypto-rsa-common"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-64621"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-64621"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64621"},{"type":"ARTICLE","url":"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-f27x-frr8-j9hc"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/freerdp-before-double-free-via-selectedmonitors"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-64624"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-64624"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64624"},{"type":"ARTICLE","url":"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-rq8f-9xjh-pr3m"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/freerdp-rdp-file-parser-remote-code-execution-via-cli-options"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-67289"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-67289"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-67289"},{"type":"ARTICLE","url":"https://github.com/FreeRDP/FreeRDP/commit/f3b4347105114fe7453828736bea069999af319f"},{"type":"ARTICLE","url":"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-mwwh-mhp9-q7vm"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/freerdp-before-http-proxy-request-injection-via-redirection"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-67299"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-67299"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-67299"},{"type":"ARTICLE","url":"https://github.com/FreeRDP/FreeRDP/commit/5370fb26fbf034ecd11d3026b6ad639b5fff493f"},{"type":"ARTICLE","url":"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-34hq-hwjw-q8v3"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/freerdp-before-use-after-free-via-windowicon-async-message"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-68580"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-68580"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-68580"},{"type":"ARTICLE","url":"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-69xf-pqrw-596x"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/freerdp-before-integer-overflow-via-audio-input-channel"}],"affected":[{"package":{"name":"freerdp","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/freerdp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:3.10.3-12.el10_2.8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:54486.json"}},{"package":{"name":"freerdp-debuginfo","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/freerdp-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:3.10.3-12.el10_2.8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:54486.json"}},{"package":{"name":"freerdp-debugsource","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/freerdp-debugsource"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:3.10.3-12.el10_2.8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:54486.json"}},{"package":{"name":"freerdp-libs","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/freerdp-libs"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:3.10.3-12.el10_2.8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:54486.json"}},{"package":{"name":"freerdp-libs-debuginfo","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/freerdp-libs-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:3.10.3-12.el10_2.8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:54486.json"}},{"package":{"name":"freerdp-server-debuginfo","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/freerdp-server-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:3.10.3-12.el10_2.8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:54486.json"}},{"package":{"name":"libwinpr","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/libwinpr"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:3.10.3-12.el10_2.8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:54486.json"}},{"package":{"name":"libwinpr-debuginfo","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/libwinpr-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:3.10.3-12.el10_2.8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:54486.json"}},{"package":{"name":"freerdp-devel","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/freerdp-devel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:3.10.3-12.el10_2.8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:54486.json"}},{"package":{"name":"freerdp-server","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/freerdp-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:3.10.3-12.el10_2.8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:54486.json"}},{"package":{"name":"libwinpr-devel","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/libwinpr-devel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:3.10.3-12.el10_2.8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:54486.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}