{"id":"SUSE-SU-2026:1633-1","summary":"Security update for freerdp","details":"This update for freerdp fixes the following issues:\n\n- CVE-2026-25941: Out-of-Bounds Read in client RDPGFX channel via crafted `WIRE_TO_SURFACE_2` PDU (bsc#1258919).\n- CVE-2026-25942: Global-buffer-overflow in `xf_rail_server_execute_result` (bsc#1258920).\n- CVE-2026-25952: Heap-use-after-free in `xf_SetWindowMinMaxInfo` (bsc#1258921).\n- CVE-2026-25953: Heap-use-after-free in `xf_AppUpdateWindowFromSurface` (bsc#1258923).\n- CVE-2026-25954: Heap-use-after-free in `xf_rail_server_local_move_size` (bsc#1258924).\n- CVE-2026-25955: Heap-use-after-free in `xf_AppUpdateWindowFromSurface` (bsc#1258973).\n- CVE-2026-25959: Heap-use-after-free in `xf_cliprdr_provide_data_` (bsc#1258976).\n- CVE-2026-25997: Heap-use-after-free in `xf_clipboard_format_equal` (bsc#1258977).\n- CVE-2026-26986: Heap-use-after-free in `rail_window_free` (bsc#1258967).\n- CVE-2026-27015: Smartcard NDR alignment padding triggers reachable `WINPR_ASSERT` abort (bsc#1258987).\n- CVE-2026-27950: Denial of service due to incomplete fix for heap-use-after-free vulnerability (bsc#1258941).\n- CVE-2026-27951: Denial of service via endless blocking loop in `Stream_EnsureCapacity` (bsc#1258939).\n- CVE-2026-29774: Missing bounds validation can cause a client-side heap buffer overflow (bsc#1259689).\n- CVE-2026-29775: Malicious server can trigger a client-side heap out-of-bounds access (bsc#1259684).\n- CVE-2026-29776: Missing length check can lead to an integer underflow (bsc#1259692).\n- CVE-2026-31897: Missing length check can cause an out-of-bounds read (bsc#1259693).\n","modified":"2026-04-28T08:00:19.514870Z","published":"2026-04-27T12:05:30Z","related":["CVE-2026-25941","CVE-2026-25942","CVE-2026-25952","CVE-2026-25953","CVE-2026-25954","CVE-2026-25955","CVE-2026-25959","CVE-2026-25997","CVE-2026-26986","CVE-2026-27015","CVE-2026-27950","CVE-2026-27951","CVE-2026-29774","CVE-2026-29775","CVE-2026-29776","CVE-2026-31884","CVE-2026-31897"],"upstream":["CVE-2026-25941","CVE-2026-25942","CVE-2026-25952","CVE-2026-25953","CVE-2026-25954","CVE-2026-25955","CVE-2026-25959","CVE-2026-25997","CVE-2026-26986","CVE-2026-27015","CVE-2026-27950","CVE-2026-27951","CVE-2026-29774","CVE-2026-29775","CVE-2026-29776","CVE-2026-31884","CVE-2026-31897"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20261633-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258919"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258920"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258921"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258923"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258924"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258939"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258941"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258967"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258973"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258976"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258977"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258987"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259680"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259684"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259689"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259692"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259693"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25941"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25942"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25952"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25953"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25954"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25955"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25959"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25997"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-26986"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27015"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27950"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27951"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-29774"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-29775"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-29776"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31884"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31897"}],"schema_version":"1.7.5"}