{"id":"openSUSE-SU-2026:21116-1","summary":"Security update for freerdp","details":"This update for freerdp fixes the following issues\n\nUpdate to version 3.26.0:\n\n- CVE-2026-33982: heap-buffer-overflow READ vulnerability at 24 bytes before the allocation, in\n  winpr_aligned_offset_recalloc() (bsc#1261222).\n- CVE-2026-33985: FreeRDP: Information disclosure via heap memory out of bounds read (bsc#1261217).\n- CVE-2026-33986: heap OOB write due to H.264 YUV buffer dimension desync (bsc#1261223).\n- CVE-2026-33987: heap OOB write due to persistent cache bmpSize desync (bsc#1261226).\n- CVE-2026-33995: double-free vulnerability in kerberos_AcceptSecurityContext() and\n  kerberos_InitializeSecurityContextA() (bsc#1261227).\n- CVE-2026-40033: heap buffer overflow in `gdi_CacheToSurface` allows attackers to cause a denial of service or achieve\n  remote execute code (bsc#1266317).\n- CVE-2026-40254: off-by-one in contains_dotdot() allows drive channel path traversal (bsc#1262743).\n- CVE-2026-44420: Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-\n  side clipboard (cliprdr) channel (bsc#1267008).\n- CVE-2026-44421: Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client\n  by sending crafted RDPGFX PDUs (bsc#1267009).\n- CVE-2026-44422: Prior to 3.26.0, a malicious-server-triggerable heap use-after-free / double-free in the FreeRDP\n  client's RDPEAR authentication-redirection path exists (bsc#1267010).\n- CVE-2026-45700: n attacker can bypass the check with a large nDstStep and a large nXDst, causing\n  planar_decompress_plane_rle() to write past the end of pTempData (bsc#1267011).\n\nChanges:\n\n * cmake: Findyuv: Use correct pkgconfig name (#12666)\n * Remove deallocator attribute from rfx_message_free (#12681)\n * [winpr,utils] improve winpr/ntlm.h (#12677)\n * rdpecam-v4l: stop the capture thread when streaming is cleared (#12690)\n * fix(winpr,ncrypt): support PIV retired key slots for smartcard logon (#12684)\n * [core,instance] fix deprecation guards (#12691)\n * [ci,alt-arch] enable internal MD4, MD5 and RC4 (#12692)\n * Add VideoToolbox H.264 support for ffmpeg (#12694)\n * [client,common] add /args-from:file: syntax (#12697)\n * [ci,freebsd] update freebsd builds (#12698, #12700, #12701, #12702)\n * [client, android] UI modernization, SQLCipher and more (#12685, #12686, #12687, #12730,\n * #12731, #12736, #12737, #12688)\n * [cmake,deps] use alias target for sso-mib (#12706)\n * [core,settings] add auto reconnect triggered flag (#12709)\n * Force YUV420P when videotoolbox is used (#12711)\n * Release cleanups (#12712)\n * [gdi,gfx] fix bounds checks and proxy unit tests (#12713)\n * Improved input checks (#12714)\n * [winpr,utils] add unit tests for command line parser (#12716)\n * Cmdline fixes (#12717)\n * [codec,planar] fix bounds checks (#12718)\n * [client,common] add freerdp_client_settings_parse_command_line_argume... (#12724)\n * [winpr,sspi] clean up ntlm code (#12732)\n * Experimental AV1 support has been added. This currently works only with FreeRDP based servers.\n * Most notably there is now support for [MS-RDPEWA] (FIDO2 redirection)\n * Android client received a (small) facelift\n * Improved SDL3 client drawing performance\n * Console output support for SDL3 (windows) and windows native client\n * RDP proxy now supports NSCodec and RFX modes.\n * RDP PRoxy now has smartcard emulation and SAM file support (via config file)\n * Smartcard KSP support for NLA authentication\n * [winpr,wlog] add WLog_SetGlobalPrefix (#12497)\n * [channels,video] fix wrong cast (#12511)\n * [codec,openh264] reject encoder ABI mismatch on runtime-loaded library (#12510)\n * [client,sdl] create a copy of rdpPointer (#12512)\n * [codec,video] properly pass intermediate format (#12518)\n * [utils, signal] lazily initialize Windows CRITICAL_SECTION to match POSIX static mutex behavior (#12520)\n * winpr: improve libunwind backtraces (#12530)\n * [server,shadow] remember selected caps (#12528)\n * Zero credential data before free in NLA and NTLM context (#12532)\n * [server,proxy] ignore missing client in input channel (#12536)\n * [server,proxy] ignore rdpdr messages (#12537)\n * [winpr,sspi] improve kerberos logging (#12538)\n * Codec fixes (#12542)\n * [winpr,sspi] Fix context nullptr handling (#12543)\n * Dev 3.24.3 dev0 (#12545)\n * Fix memory leak in gdi_create_bitmap() on gdi_CreateBitmap failure (libfreerdp/gdi/graphics.c) (#12547)\n * Fix memory leak in vgids_read_do_fkt() on Stream_New failure (libfreerdp/emu/scard/smartcard_virtual_gids.c) (#12548)\n * Proxy config improve (#12549)\n * Proxy config improve (#12550)\n * [client,sdl] clamp cursor hotspot (#12553)\n * RFC: Research/av1 codec extension (#12527)\n * [winpr,kerberos] fix krb_log_context_encryption (#12555)\n * [client,sdl] fix global init return check (#12558)\n * Fix remote credential with windows11h2 (#12560)\n * Proxy scard auth improvements (#12561)\n * [winpr,sspi] guard krb5_get_etype_info (#12562)\n * [utils,smartcard] fix STATUS_BUFFER_TOO_SMALL (#12564)\n * [client,common] do not manipulate security settings for smartcard-logon (#12567)\n * [channels,audin] fix regression for microphone (#12570)\n * [client,sdl] add SDL_KMOD_MODE and SDL_KMOD_LEVEL5 (#12569)\n * Fix unbound strlen on slotDescription (#12571)\n * build: Update FindFFmpeg.cmake to support Apple frameworks with 'lib' prefix (#12565)\n * [channels,rdpewa] add WebAuthn virtual channel support (#12572)\n * [core] fix freerdp_get_nla_sspi_error always returning 0 on client (#12574)\n * [ci] enable rdpewa channel (#12576)\n * small refactoring (#12578)\n * Rdpewa unify notifications (#12581)\n * [client,sdl] fix crash when clicking 'cancel' on PIN popup (#12580)\n * [channels,drive] refine bounds checks (#12584)\n * fix: smartcard logon with ECC keys and minidriver-assigned container names (#12585)\n * Various papercuts (#12583)\n * fix: console output on Windows client (#12573)\n * [winpr,crt] dump stack on aligned memory errors (#12588)\n * [client,x11] keep scancode input for Ctrl/Alt/Super combinations in /kbd:unicode mode (#12590)\n * [codec,progressive] fix underflow guard in progressive_rfx_quant_sub (#12592)\n * fix: wfreerdp floatbar visibility (#12594)\n * [winpr,json] return a copy from WINPR_JSON_Print* (#12595)\n * [client,sdl] drop WITH_DEBUG_SDL_EVENTS (#12599)\n * Ncrypt and asn1 cleanup (#12604)\n * Video channel fix (#12593)\n * [codec,h264] fix media foundation backend (#12606)\n * fix(sdl): detect Hyprland and river in tryFallback() (#12608)\n * Proxy stress fixes (#12597)\n * Add new fuzzer tests (#12613)\n * fix(sdl): use SDL_Renderer instead of software surfaces (#12607)\n * fix(sdl): BFS neighbor walk pop/begin mismatch in addOrUpdateDisplay (#12614)\n * fix(sdl): promote first monitor as primary when subset excludes primary (#12618)\n * [ci,android] default to only aarch64 (#12622)\n * Fix process exit code on non-pidfd platforms (macOS, BSD)#12534) (#12586)\n * warning cleanups (#12626)\n * fix: prevent PostQuitMessage in RemoteApp WM_DESTROY handler (#12629)\n * [winpr,ntlm] fix message cleanup across the SSPI lifecycle (#12609)\n * Code bug fixes (#12632)\n * Oss fixes (#12633)\n * [client,android] add an option to enable keeping screen on when connected (#12630)\n * [client, android] Fix layout overlaps, migrate to AndroidX, and update UI components (#12628)\n * Proxy config tests (#12636)\n * Proxy config optional targethost (#12637)\n * [client,sdl] set SDL_HINT_SCREENSAVER_INHIBIT_ACTIVITY_NAME (#12639)\n * Nightly deb fix (#12640, #12641, #12649, #12650, #12642, #12643)\n * [winpr,input] fix korean keyboard mapping (#12646)\n * [client,sdl] set hints before SDL_Init (#12644)\n * Sdl inhibit option (#12647)\n * [client,X11] fix residual race in xf_clipboard_formats_free (#12648)\n * (sdl3): Fix oversized window on HiDPI Wayland (#12635)\n * [cache,bitmap] fix off-by-one in bitmap_cache_put bounds check (#12651)\n * [winpr,sspi] free fields buffer immediately (#12654)\n * [codec,dsp] fix fencepost error in dsp_ima_clamp_step (#12655)\n * RDPECAM MJPEG support\n * Support for FDK-AAC for sound and microphone redirection\n * Support timezones as JSON resources\n * Rely preferably on pkgconfig to pull devel packages instead of\n * A new option /cert that unifies all certificate related options (gh#FreeRDP/FreeRDP#5880)\n","modified":"2026-06-30T18:24:51.573584727Z","published":"2026-06-20T06:54:39Z","related":["CVE-2026-33982","CVE-2026-33985","CVE-2026-33986","CVE-2026-33987","CVE-2026-33995","CVE-2026-40033","CVE-2026-40254","CVE-2026-44420","CVE-2026-44421","CVE-2026-44422","CVE-2026-45700"],"upstream":["CVE-2026-33982","CVE-2026-33985","CVE-2026-33986","CVE-2026-33987","CVE-2026-33995","CVE-2026-40033","CVE-2026-40254","CVE-2026-44420","CVE-2026-44421","CVE-2026-44422","CVE-2026-45700"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1174200"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261217"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261222"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261223"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261226"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261227"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262743"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266317"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267008"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267009"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267010"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267011"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33982"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33985"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33986"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33987"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33995"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40033"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40254"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44420"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44421"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44422"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45700"}],"affected":[{"package":{"name":"freerdp","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/freerdp&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.26.0-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"librdtk0-0":"3.26.0-160000.1.1","freerdp-proxy-plugins":"3.26.0-160000.1.1","libwinpr3-3":"3.26.0-160000.1.1","freerdp-wayland":"3.26.0-160000.1.1","rdtk0-devel":"3.26.0-160000.1.1","freerdp-sdl":"3.26.0-160000.1.1","freerdp":"3.26.0-160000.1.1","freerdp-devel":"3.26.0-160000.1.1","winpr-devel":"3.26.0-160000.1.1","libfreerdp3-3":"3.26.0-160000.1.1","libfreerdp-server-proxy3-3":"3.26.0-160000.1.1","uwac0-devel":"3.26.0-160000.1.1","libuwac0-0":"3.26.0-160000.1.1","freerdp-proxy":"3.26.0-160000.1.1","freerdp-server":"3.26.0-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21116-1.json"}}],"schema_version":"1.7.5"}