{"id":"SUSE-SU-2026:3562-1","summary":"Security update for freerdp","details":"This update for freerdp fixes the following issues:\n\n- CVE-2026-27951: 32-bit system denial of service via endless blocking loop in `Stream_EnsureCapacity` (bsc#1258939).\n- CVE-2026-33952: client denial of service via unvalidated authentication length field (bsc#1261196).\n- CVE-2026-33977: client denial of service via malformed IMA ADPCM audio data (bsc#1261198).\n- CVE-2026-33982: heap buffer overread in `winpr_aligned_offset_recalloc()` can lead to undefined behavior\n  (bsc#1261222).\n- CVE-2026-33983: improper error handling can lead to use of incorrect shift exponent, undefined behavior and an 80\n  billion iteration loop (bsc#1261200).\n- CVE-2026-33984: heap buffer overflow allows arbitrary code execution via crafted pixel data (bsc#1261211).\n- CVE-2026-33985: heap out-of-bounds read can leak sensitive data when pixel data is rendered to screen (bsc#1261217).\n- CVE-2026-33986: heap out-of-bounds write due to H.264 YUV buffer dimension desync (bsc#1261223).\n- CVE-2026-33987: heap out-of-bounds write due to persistent cache `bmpSize` desync (bsc#1261226).\n- CVE-2026-33995: double-free in `kerberos_AcceptSecurityContext()` and `kerberos_InitializeSecurityContextA()` can\n  lead to crash during NLA connection teardown with a failed authentication attempt (bsc#1261227).\n- CVE-2026-40033: heap buffer overflow in `gdi_CacheToSurface` allows attackers to cause a denial of service or achieve\n  remote code execution (bsc#1266317).\n- CVE-2026-40254: off-by-one error in `contains_dotdot()` allows for drive channel path traversal (bsc#1262743).\n- CVE-2026-44420: heap buffer overwrite can be triggered in server-side clipboard channel when a malicious client sends\n  a `CB_CLIP_CAPS` PDU with a too-small `capabilitySetLength` (bsc#1267008).\n- CVE-2026-44421: improper validation in `gdi_CacheToSurface` can lead to a heap buffer overwrite client when an RDP\n  server sends crafted RDPGFX PDUs (bsc#1267009).\n- CVE-2026-44422: improper memory management can lead to heap use-after-free/double-free in a client's RDPEAR\n  authentication-redirection path (bsc#1267010).\n- CVE-2026-45700: data check bypass when decoding RLE planar data can lead to an out-of-bounds heap write\n  (bsc#1267011).\n- CVE-2026-56297: improper synchronization of `channel_callback` access can lead to use-after-free in\n  `dvcman_channel_close` and `dvcman_call_on_receive` triggered by a malicious RDP server (bsc#1271071).\n- CVE-2026-57156: integer overflow in `update_read_delta_points` allows malicious RDP peers to cause a heap buffer\n  overflow (bsc#1271303).\n- CVE-2026-57157: 2-byte heap out-of-bounds read via attacker-supplied MS-RDPECAM `DeviceName` and `VirtualChannelName`\n  fields (bsc#1271304).\n- CVE-2026-57158: incomplete fix for CVE-2026-23530 in `planar_decompress_plane_rle_only` allows a malicious RDP server\n  to trigger a one byte buffer overflow via a truncated `RDPGFX_CMDID_WIRETOSURFACE_1` planar payload (bsc#1271305).\n","modified":"2026-08-12T10:45:04.852427998Z","published":"2026-08-10T18:16:39Z","related":["CVE-2026-27951","CVE-2026-33952","CVE-2026-33977","CVE-2026-33982","CVE-2026-33983","CVE-2026-33984","CVE-2026-33985","CVE-2026-33986","CVE-2026-33987","CVE-2026-33995","CVE-2026-40033","CVE-2026-40254","CVE-2026-44420","CVE-2026-44421","CVE-2026-44422","CVE-2026-45700","CVE-2026-56297","CVE-2026-57156","CVE-2026-57157","CVE-2026-57158"],"upstream":["CVE-2026-27951","CVE-2026-33952","CVE-2026-33977","CVE-2026-33982","CVE-2026-33983","CVE-2026-33984","CVE-2026-33985","CVE-2026-33986","CVE-2026-33987","CVE-2026-33995","CVE-2026-40033","CVE-2026-40254","CVE-2026-44420","CVE-2026-44421","CVE-2026-44422","CVE-2026-45700","CVE-2026-56297","CVE-2026-57156","CVE-2026-57157","CVE-2026-57158"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263562-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258939"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261196"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261198"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261200"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261211"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261217"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261222"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261223"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261226"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261227"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262743"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266317"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267008"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267009"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267010"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267011"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271071"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271303"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271304"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271305"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27951"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33952"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33977"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33982"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33983"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33984"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33985"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33986"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33987"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33995"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40033"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40254"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44420"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44421"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44422"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45700"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56297"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-57156"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-57157"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-57158"}],"affected":[{"package":{"name":"freerdp","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP7","purl":"pkg:rpm/suse/freerdp&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.10.3-150700.3.17.1"}]}],"ecosystem_specific":{"binaries":[{"libuwac0-0":"3.10.3-150700.3.17.1","freerdp":"3.10.3-150700.3.17.1","freerdp-devel":"3.10.3-150700.3.17.1","freerdp-proxy":"3.10.3-150700.3.17.1","freerdp-server":"3.10.3-150700.3.17.1","freerdp-wayland":"3.10.3-150700.3.17.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3562-1.json"}},{"package":{"name":"freerdp","ecosystem":"SUSE:Linux Enterprise Workstation Extension 15 SP7","purl":"pkg:rpm/suse/freerdp&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.10.3-150700.3.17.1"}]}],"ecosystem_specific":{"binaries":[{"freerdp-proxy":"3.10.3-150700.3.17.1","freerdp-sdl":"3.10.3-150700.3.17.1","freerdp-proxy-plugins":"3.10.3-150700.3.17.1","freerdp-server":"3.10.3-150700.3.17.1","winpr-devel":"3.10.3-150700.3.17.1","freerdp-devel":"3.10.3-150700.3.17.1","libfreerdp3-3":"3.10.3-150700.3.17.1","libfreerdp-server-proxy3-3":"3.10.3-150700.3.17.1","freerdp":"3.10.3-150700.3.17.1","libwinpr3-3":"3.10.3-150700.3.17.1","librdtk0-0":"3.10.3-150700.3.17.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3562-1.json"}}],"schema_version":"1.9.0"}