{"id":"openSUSE-SU-2026:20657-1","summary":"Security update for freerdp","details":"This update for freerdp fixes the following issues:\n\nUpdate to version 3.24.2.\n\nSecurity issues fixed:\n\n- CVE-2026-25941: out-of-bounds read in the FreeRDP client RDPGFX channel (bsc#1258919).\n- CVE-2026-25942: buffer overflow of global array in `xf_rail_server_execute_result` (bsc#1258920).\n- CVE-2026-25952: heap use-after-free in `xf_SetWindowMinMaxInfo` (bsc#1258921).\n- CVE-2026-25953: heap use-after-free in `xf_AppUpdateWindowFromSurface` (bsc#1258923).\n- CVE-2026-25954: heap use-after-free in `xf_rail_server_local_move_size` (bsc#1258924).\n- CVE-2026-25955: heap use-after-free in `xf_AppUpdateWindowFromSurface` (bsc#1258973).\n- CVE-2026-25959: heap use-after-free in `xf_cliprdr_provide_data_` (bsc#1258976).\n- CVE-2026-25997: heap use-after-free in `xf_clipboard_format_equal` (bsc#1258977).\n- CVE-2026-26271: buffer overread in FreeRDP icon processing (bsc#1258979).\n- CVE-2026-26955: out-of-bounds write in FreeRDP clients using the GDI surface pipeline (bsc#1258982).\n- CVE-2026-26965: out-of-bounds write in FreeRDP client RLE planar decode path (bsc#1258985).\n- CVE-2026-29774: heap buffer overflow in the FreeRDP client's AVC420/AVC444 YUV-to-RGB conversion path (bsc#1259689).\n- CVE-2026-29775: out-of-bounds access in the FreeRDP client bitmap cache subsystem (bsc#1259684).\n- CVE-2026-29776: integer underflow in `update_read_cache_bitmap_order` (bsc#1259692).\n- CVE-2026-31806: heap buffer overflow in `nsc_process_message` (bsc#1259653).\n- CVE-2026-31883: heap buffer overwrite due to a `size_t` underflow in the IMA-ADPCM and MS-ADPCM audio decoders\n  (bsc#1259679).\n- CVE-2026-31884: division by zero in MS-ADPCM and IMA-ADPCM decoders (bsc#1259680).\n- CVE-2026-31885: out-of-bounds read in MS-ADPCM and IMA-ADPCM decoders (bsc#1259686).\n- CVE-2026-31897: out-of-bounds read in `freerdp_bitmap_decompress_planar` (bsc#1259693).\n- CVE-2026-33952: client-side crash due to `WINPR_ASSERT()` failure in `rts_read_auth_verifier_no_checks()`\n  (bsc#1261196).\n- CVE-2026-33977: client-side crash due to `WINPR_ASSERT()` failure in IMA ADPCM audio decoder (bsc#1261198).\n- CVE-2026-33982: heap buffer overread in in `winpr_aligned_offset_recalloc` (bsc#1261222).\n- CVE-2026-33983: undefined behavior and resource exhaustion via 80 billion iteration loop in\n  `progressive_decompress_tile_upgrade` (bsc#1261200).\n- CVE-2026-33984: heap buffer overflow in ClearCodec `resize_vbar_entry` (bsc#1261211).\n- CVE-2026-33985: heap out-of-bounds read in `clear_decompress_glyph_data` (bsc#1261217).\n- CVE-2026-33986: heap out-of-bounds write due to H.264 YUV buffer dimension desync (bsc#1261223).\n- CVE-2026-33987: heap out-of-bounds write due to persistent cache bmpSize desync (bsc#1261226).\n- CVE-2026-33995: double-free vulnerability in `kerberos_AcceptSecurityContext` and\n  `kerberos_InitializeSecurityContextA` (bsc#1261227).\n\nOther updates and bugfixes:\n\n- Version 3.24.2:\n  * [channels,video] fix wrong cast (#12511)\n  * [codec,openh264] reject encoder ABI mismatch on runtime-loaded library (#12510)\n  * [client,sdl] create a copy of rdpPointer (#12512)\n  * [codec,video] properly pass intermediate format (#12518)\n  * [utils, signal] lazily initialize Windows CRITICAL_SECTION to match POSIX static mutex behavior (#12520) winpr:\n    improve libunwind backtraces (#12530)\n  * [server,shadow] remember selected caps (#12528)\n  * Zero credential data before free in NLA and NTLM context (#12532)\n  * [server,proxy] ignore missing client in input channel (#12536)\n  * [server,proxy] ignore rdpdr messages (#12537)\n  * [winpr,sspi] improve kerberos logging (#12538)\n  * Codec fixes (#12542)\n\n- Version 3.24.1:\n  * [warnings] fix various sign and cast warnings (#12480)\n  * [client,x11] start with xfc-\u003eremote_app = TRUE; (#12491)\n  * Sam file read regression fix (#12484)\n  * [ncrypt,smartcardlogon] support ECC keys in PKCS#11 smartcard enumeration (#12490)\n  * Fix: memory leak in rdp_client_establish_keys() (#12494)\n  * Fix memory leak in freerdp_settings_int_buffer_copy() on error paths (libfreerdp/core/settings.c) (#12486)\n  * Code Cleanups (#12493)\n  * Fix: memory leak in PCSC_SCardListReadersW() (#12495)\n  * [channels,telemetry] use dynamic logging (#12496)\n  * [channel,gfx] use generic plugin log (@12498, #12499)\n  * [channels,audin] set error when audio_format_read fails (#12500)\n  * [channels,video] unify error handling (#12502)\n  * Fastpath fine grained lock (#12503)\n  * [core,update] make the PlaySound callback non-mandatory (#12504)\n  * Refinements: RPM build updates, FIPS improvements (#12506)\n\n- Version 3.24.0:\n  * Completed the [[nodiscard]] marking of the API to warn about problematic\n  * unchecked use of functions\n  * Added full C23 support (default stays at C11) to allow new compilers\n  * to do stricter checking\n  * Improved X11 and SDL3 clients\n  * Improved smartcard support\n  * proxy now supports RFX graphics mode\n  * Attribute nodiscard related chanes (#12325, #12360, #12395, #12406, #12421, #12426, #12177, #12403, #12405, #12407,\n    #12409, #12408, #12412, #12413)\n  * c23 related improvements (#12368, #12371, #12379, #12381, #12383, #12385, #12386, #12387, #12384)\n  * Generic code cleanups (#12382, #12439, #12455, #12462, #12399, #12473) [core,utils] ignore NULL values in\n    remove_rdpdr_type (#12372)\n  * [codec,fdk] revert use of WinPR types (#12373)\n  * [core,gateway] ignore incomplete rpc header (#12375, #12376)\n  * [warnings] make function declaration names consistent (#12377)\n  * [libfreerdp] Add new define for logon error info (#12380)\n  * [client,x11] improve rails window locking (#12392)\n  * Reload fix missing null checks (#12396)\n  * Bounds checks (#12400)\n  * [server,proxy] check for nullptr before using scard_call_context (#12404)\n  * [uwac] fix rectangular glitch around surface damage regions (#12410)\n  * Address various error handling inconsistencies (#12411)\n  * [core,server] Improve WTS API locking (#12414)\n  * Address some GCC compile issues (#12415, #12420)\n  * Winpr atexit (#12416)\n  * [winpr,smartcard] fix function pointer casts (#12422)\n  * Xf timer fix (#12423)\n  * [client,sdl] workaround for wlroots compositors (#12425)\n  * [client,sdl] fix SdlWindow::query (#12378)\n  * [winpr,smartcard] fix PCSC_ReleaseCardContext (#12427)\n  * [client,x11] eliminate obsolete compile flags (#12428)\n  * [client,common] skip sending input events when not connected (#12429)\n  * Input connected checks (#12430)\n  * Floatbar and display channel improvements (#12431)\n  * [winpr,platform] fix WINPR_ATTR_NODISCARD definition (#12432)\n  * [client] Fix writing of gatewayusagemethod to .rdp files (#12433)\n  * Nodiscard finetune (#12435)\n  * [core] fix missing gateway credential sync (#12436)\n  * [client,sdl3] limit FREERDP_WLROOTS_HACK (#12441)\n  * [core,settings] Allow FreeRDP_instance in setter (#12442)\n  * [codec,h264] make log message trace (#12444)\n  * X11 rails improve (#12440)\n  * [codec,nsc] limit copy area in nsc_process_message (#12448)\n  * Proxy support RFX and NSC settings (#12449)\n  * [client,common] display a shortened help on parsing issues (#12450)\n  * [winpr,smartcard] refine locking for pcsc layer (#12451)\n  * [codec,swscale] allow runtime loading of swscale (#12452)\n  * Swscale fallback (#12454)\n  * Sdl multi scaling support (#12456)\n  * [packaging,flatpak] update runtime and dependencies (#12457)\n  * [codec,video] add doxygen version details (#12458)\n  * [github,templates] update templates (#12460)\n  * [client,sdl] allow FREERDP_WLROOTS_HACK for all sessions (#12461)\n  * [warnings,nodiscard] add log messages for failures (#12463)\n  * [gdi,gdi] ignore empty rectangles (#12467)\n  * Smartcard fix smartcard-login, pass rdpContext for abort (#12466)\n  * [winpr,smartcard] fix compiler warnings (#12469)\n  * [winpr,timezone] fix search for transition dates (#12468)\n  * [client,common] improve /p help (#12471)\n  * Scard logging refactored (#12472)\n  * [emu,scard] fix smartcard emulation (#12475)\n  * Sdl null cursor (#12474)\n\n- Version 3.23.0:\n  * Sdl cleanup (#12202)\n  * [client,sdl] do not apply window offset (#12205)\n  * [client,sdl] add SDL_Error to exceptions (#12214)\n  * Rdp monitor log (#12215)\n  * [winpr,smartcard] implement some attributes (#12213)\n  * [client,windows] Fix return value checks for mouse event functions (#12279)\n  * [channels,rdpecam] fix sws context checks (#12272)\n  * [client,windows] Enhance error handling and context validation (#12264)\n  * [client,windows] Add window handle validation in RDP_EVENT_TYPE_WINDOW_NEW (#12261)\n  * [client,sdl] fix multimon/fullscreen on wayland (#12248)\n  * Vendor by app (#12207)\n  * [core,gateway] relax TSG parsing (#12283)\n  * [winpr,smartcard] simplify PCSC_ReadDeviceSystemName (#12273)\n  * [client,windows] Implement complete keyboard indicator synchronization (#12268)\n  * Fixes more more more (#12286)\n  * Use application details for names (#12285)\n  * warning cleanups (#12289)\n  * Warning cleanup (#12291)\n  * [client,windows] Enhance memory safety with NULL checks and resource protection (#12271)\n  * [client,x11] apply /size:xx% only once (#12293)\n  * Freerdp config test (#12295)\n  * [winpr,smartcard] fix returned attribute length (#12296)\n  * [client,SDL3] Fix properly handle smart-sizing with fullscreen (#12298)\n  * [core,test] fix use after free (#12299)\n  * Sign warnings (#12300)\n  * [cmake,compiler] disable -Wjump-misses-init (#12301)\n  * [codec,color] fix input length checks (#12302)\n  * [client,sdl] improve cursor updates, fix surface sizes (#12303)\n  * Sdl fullscreen (#12217)\n  * [client,sdl] fix move constructor of SdlWindow (#12305)\n  * [utils,smartcard] check stream length on padding (#12306)\n  * [android] Fix invert scrolling default value mismatch (#12309)\n  * Clear fix bounds checks (#12310)\n  * Winpr attr nodiscard fkt ptr (#12311)\n  * [codec,planar] fix missing destination bounds checks (#12312)\n  * [codec,clear] fix destination checks (#12315)\n  * NSC Codec fixes (#12317)\n  * Freerdp api nodiscard (#12313)\n  * [allocations] fix growth of preallocated buffers (#12319)\n  * Rdpdr simplify (#12320)\n  * Resource fix (#12323)\n  * [winpr,utils] ensure message queue capacity (#12322)\n  * [server,shadow] fix return and parameter checks (#12330)\n  * Shadow fixes (#12331)\n  * [rdtk,nodiscard] mark rdtk API nodiscard (#12329)\n  * [client,x11] fix XGetWindowProperty return handling (#12334)\n  * Win32 signal (#12335)\n  * [channel,usb] fix message parsing and creation (#12336)\n  * [cmake] Define WINPR_DEFINE_ATTR_NODISCARD (#12338)\n  * Proxy config fix (#12345)\n  * [codec,progressive] refine progressive decoding (#12347)\n  * [client,sdl] fix sdl_Pointer_New (#12350)\n  * [core,gateway] parse [MS-TSGU] 2.2.10.5 HTTP_CHANNEL_RESPONSE_OPTIONAL (#12353)\n  * X11 kbd sym (#12354)\n  * Windows compile warning fixes (#12357,#12358,#12359)\n","modified":"2026-05-05T18:24:22.528764Z","published":"2026-04-30T16:54:03Z","related":["CVE-2026-25941","CVE-2026-25942","CVE-2026-25952","CVE-2026-25953","CVE-2026-25954","CVE-2026-25955","CVE-2026-25959","CVE-2026-25997","CVE-2026-26271","CVE-2026-26955","CVE-2026-26965","CVE-2026-29774","CVE-2026-29775","CVE-2026-29776","CVE-2026-31806","CVE-2026-31883","CVE-2026-31884","CVE-2026-31885","CVE-2026-31897","CVE-2026-33952","CVE-2026-33977","CVE-2026-33982","CVE-2026-33983","CVE-2026-33984","CVE-2026-33985","CVE-2026-33986","CVE-2026-33987","CVE-2026-33995"],"upstream":["CVE-2026-25941","CVE-2026-25942","CVE-2026-25952","CVE-2026-25953","CVE-2026-25954","CVE-2026-25955","CVE-2026-25959","CVE-2026-25997","CVE-2026-26271","CVE-2026-26955","CVE-2026-26965","CVE-2026-29774","CVE-2026-29775","CVE-2026-29776","CVE-2026-31806","CVE-2026-31883","CVE-2026-31884","CVE-2026-31885","CVE-2026-31897","CVE-2026-33952","CVE-2026-33977","CVE-2026-33982","CVE-2026-33983","CVE-2026-33984","CVE-2026-33985","CVE-2026-33986","CVE-2026-33987","CVE-2026-33995"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258919"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258920"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258921"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258923"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258924"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258973"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258976"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258977"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258979"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258982"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258985"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259653"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259679"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259680"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259684"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259686"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259689"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259692"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259693"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261196"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261198"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261200"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261211"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261217"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261222"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261223"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261226"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261227"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25941"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25942"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25952"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25953"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25954"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25955"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25959"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25997"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-26271"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-26955"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-26965"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-29774"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-29775"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-29776"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31806"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31883"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31884"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31885"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31897"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33952"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33977"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33982"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33983"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33984"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33985"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33986"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33987"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33995"}],"schema_version":"1.7.5"}