{"id":"openSUSE-SU-2026:20632-1","summary":"Security update for freerdp2","details":"This update for freerdp2 fixes the following issues:\n\nChanges in freerdp2:\n\n- Update freerdp-3-macro:\n  + Add WINPR_ATTR_MALLOC macro from freerdp 3\n\n- Security fixes for the following issues:\n  * CVE-2026-25941: Fixed a out of bounds read (bsc#1258919)\n  * CVE-2026-25942: Fixed a buffer overflow in xf_rail_server_execute_result() (bsc#1258920)\n  * CVE-2026-27951: Fixed a denial of service in Stream_EnsureCapacity() (bsc#1258939)\n  * CVE-2026-25997: Fixed a use-after-free in xf_clipboard_format_equal() (bsc#1258977)\n  * CVE-2026-26986: Fixed a use-after-free in rail_window_free() (bsc#1258967)\n  * CVE-2026-27015: Fixed a client denial of service via reachable assert (bsc#1258987)\n  * CVE-2026-25952: Fixed a use-after-free in xf_SetWindowMinMaxInfo() (bsc#1258921)\n  * CVE-2026-25953: Fixed a use-after-free in xf_AppUpdateWindowFromSurface() (bsc#1258923)\n  * CVE-2026-25954: Fixed a use-after-free in xf_rail_server_local_move_size() (bsc#1258924)\n  * CVE-2026-24684: Fixed a use-after-free in play_thread() (bsc#1257991).\n  * CVE-2026-26271: Fixed a buffer overread in icon processing (bsc#1258979)\n  * CVE-2026-26955: Fixed a out of bounds write (bsc#1258982)\n  * CVE-2026-26965: Fixed a out of bounds write (bsc#1258985)\n  * CVE-2026-31806: Fixed a buffer overflow via improper validation of server messages (bsc#1259653)\n  * CVE-2026-31883: Fixed a buffer overflow via crafted audio format and wave data (bsc#1259679)\n  * CVE-2026-31885: Fixed a out of bounds read (bsc#1259686)\n  * CVE-2026-24491: Fix use-after-free that was accidentally introduced in the backport (bsc#1257981)\n  * CVE-2026-22855: Fixed a buffer overflow in smartcard_unpack_set_attrib_call() (bsc#1256721)\n  * CVE-2026-22857: Fixed a use-after-free in irp_thread_func() (bsc#1256723)\n  * CVE-2026-23533: Fixed a buffer overflow in clear_decompress_residual_data() (bsc#1256943)\n  * CVE-2026-23732: Fixed a buffer overflow in Glyph_Alloc() (bsc#1256945)\n  * CVE-2026-23883: Fixed a use-after-free (bsc#1256946)\n  * CVE-2026-23884: Fixed a use-after-free in gdi_set_bounds (bsc#1256947)\n","modified":"2026-04-29T18:24:08.957673Z","published":"2026-04-27T13:16:46Z","related":["CVE-2026-22855","CVE-2026-22857","CVE-2026-23533","CVE-2026-23732","CVE-2026-23883","CVE-2026-23884","CVE-2026-24491","CVE-2026-24684","CVE-2026-25941","CVE-2026-25942","CVE-2026-25952","CVE-2026-25953","CVE-2026-25954","CVE-2026-25997","CVE-2026-26271","CVE-2026-26955","CVE-2026-26965","CVE-2026-26986","CVE-2026-27015","CVE-2026-27951","CVE-2026-31806","CVE-2026-31883","CVE-2026-31885"],"upstream":["CVE-2026-22855","CVE-2026-22857","CVE-2026-23533","CVE-2026-23732","CVE-2026-23883","CVE-2026-23884","CVE-2026-24491","CVE-2026-24684","CVE-2026-25941","CVE-2026-25942","CVE-2026-25952","CVE-2026-25953","CVE-2026-25954","CVE-2026-25997","CVE-2026-26271","CVE-2026-26955","CVE-2026-26965","CVE-2026-26986","CVE-2026-27015","CVE-2026-27951","CVE-2026-31806","CVE-2026-31883","CVE-2026-31885"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256721"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256723"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256943"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256945"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256946"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256947"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257981"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257991"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258919"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258920"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258921"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258923"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258924"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258939"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258967"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258977"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258979"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258982"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258985"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258987"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259251"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259653"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259679"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259686"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261848"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-22855"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-22857"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23533"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23732"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23883"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23884"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-24491"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-24684"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25941"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25942"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25952"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25953"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25954"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25997"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-26271"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-26955"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-26965"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-26986"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27015"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27951"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31806"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31883"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31885"}],"schema_version":"1.7.5"}