<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T16:26:46.519207+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:6340</id>
    <title>ALSA-2026:6340 — Important: freerdp security update</title>
    <updated>2026-10-03T16:26:46.705318+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: freerdp, AlmaLinux:9: freerdp-devel, AlmaLinux:9: freerdp-libs, AlmaLinux:9: libwinpr, AlmaLinux:9: libwinpr-devel</p>
<p>FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.</p>
<p>Security Fix(es):</p>
<p>* freerdp: FreeRDP heap-use-after-free (CVE-2026-22856)
  * freerdp: FreeRDP heap-buffer-overflow (CVE-2026-22854)
  * freerdp: FreeRDP heap-buffer-overflow (CVE-2026-22852)
  * freerdp: FreeRDP: Denial of Service via FastGlyph parsing buffer overflow (CVE-2026-23732)
  * freerdp: FreeRDP: Denial of Service via use-after-free in AUDIN format renegotiation (CVE-2026-24676)
  * freerdp: FreeRDP has a heap-use-after-free in video_timer (CVE-2026-24491)
  * freerdp: FreeRDP has a NULL Pointer Dereference in rdp_write_logon_info_v2() (CVE-2026-23948)
  * freerdp: FreeRDP has a Heap-use-after-free in play_thread (CVE-2026-24684)
  * freerdp: FreeRDP has a heap-use-after-free in urb_bulk_transfer_cb (CVE-2026-24681)
  * freerdp: FreeRDP has a heap-use-after-free in ainput_send_input_event (CVE-2026-24683)
  * freerdp: FreeRDP has a heap-buffer-overflow in urb_select_interface (CVE-2026-24679)
  * freerdp: FreeRDP has a Heap-use-after-free in urb_select_interface (CVE-2026-24675)
  * freerdp: FreeRDP: Arbitrary code execution via crafted Remote Desktop Protocol (RDP) server messages (CVE-2026-31806)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:6340"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-04141</id>
    <title>bdu:2026-04141</title>
    <updated>2026-10-03T16:26:46.705466+00:00</updated>
    <content>bdu:2026-04141</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-04141"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-337356</id>
    <title>EUVD-2026-337356</title>
    <updated>2026-10-03T16:26:46.705500+00:00</updated>
    <content>EUVD-2026-337356</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-337356"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-31806</id>
    <title>fkie_cve-2026-31806</title>
    <updated>2026-10-03T16:26:46.705518+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0,  the gdi_surface_bits() function processes SURFACE_BITS_COMMAND messages sent by the RDP server. When the command is handled using NSCodec, the bmp.width and bmp.height values provided by the server are not properly validated against the actual desktop dimensions. A malicious RDP server can supply crafted bmp.width and bmp.height values that exceed the expected surface size. Because these values are used during bitmap decoding and memory operations without proper bounds checking, this can lead to a heap buffer overflow. Since the attacker can also control the associated pixel data transmitted by the server, the overflow may be exploitable to overwrite adjacent heap memory. This vulnerability is fixed in 3.24.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-31806"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2036</id>
    <title>OESA-2026-2036 — freerdp security update</title>
    <updated>2026-10-03T16:26:46.705559+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP3: freerdp</p>
<p>FreeRDP is a client implementation of the Remote Desktop Protocol (RDP) that follows Microsoft&amp;amp;apos;s open specifications. This package provides the client applications xfreerdp.

Security Fix(es):</p>
<p>FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a malicious RDP server can trigger a heap buffer overflow in FreeRDP clients using the GDI surface pipeline (e.g., `xfreerdp`) by sending an RDPGFX ClearCodec surface command with an out-of-bounds destination rectangle. The `gdi_SurfaceCommand_ClearCodec()` handler does not call `is_within_surface()` to validate the command rectangle against the destination surface dimensions, allowing attacker-controlled `cmd-&amp;gt;left`/`cmd-&amp;gt;top` (and subcodec rectangle offsets) to reach image copy routines that write into `surface-&amp;gt;data` without bounds enforcement. The OOB write corrupts an adjacent `gdiGfxSurface` struct&amp;apos;s `codecs*` pointer with attacker-controlled pixel data, and corruption of `codecs*` is sufficient to reach an indirect function pointer call (`NSC_CONTEXT.decode` at `nsc.c:500`) on a subsequent codec command — full instruction pointer (RIP) control demonstrated in exploitability harness. Users should upgrade to version 3.23.0 to receive a patch.(CVE-2026-26955)</p>
<p>FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, in the RLE planar decode path, `planar_decompress_plane_rle()` writes into `pDstData` at `((nYDst+y) * nDstStep) + (4*nXD…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2036"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10408-1</id>
    <title>openSUSE-SU-2026:10408-1 — freerdp-3.24.1-1.1 on GA media</title>
    <updated>2026-10-03T16:26:46.705645+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>freerdp-3.24.1-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10408-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:10076</id>
    <title>RHSA-2026:10076 — Red Hat Security Advisory: freerdp security update</title>
    <updated>2026-10-03T16:26:46.705704+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>freerdp: FreeRDP heap-buffer-overflow freerdp: FreeRDP heap-buffer-overflow freerdp: FreeRDP heap-use-after-free freerdp: FreeRDP: Denial of Service via FastGlyph parsing buffer overflow freerdp: FreeRDP has a NULL Pointer Dereference in rdp_write_logon_info_v2() freerdp: FreeRDP has a heap-use-after-free in video_timer freerdp: FreeRDP has a Heap-use-after-free in urb_select_interface freerdp: FreeRDP: Denial of Service via use-after-free in AUDIN format renegotiation freerdp: FreeRDP has a heap-buffer-overflow in urb_select_interface freerdp: FreeRDP has a Heap-use-after-free in play_thread freerdp: FreeRDP: Arbitrary code execution via crafted Remote Desktop Protocol (RDP) server messages</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:10076"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:1129-1</id>
    <title>SUSE-SU-2026:1129-1 — Security update for freerdp</title>
    <updated>2026-10-03T16:26:46.705796+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for freerdp</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:1129-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-31806</id>
    <title>UBUNTU-CVE-2026-31806</title>
    <updated>2026-10-03T16:26:46.705830+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: freerdp, Ubuntu:Pro:18.04:LTS: freerdp2, Ubuntu:18.04:LTS: freerdp, Ubuntu:Pro:20.04:LTS: freerdp2, Ubuntu:22.04:LTS: freerdp2, Ubuntu:24.04:LTS: freerdp3, Ubuntu:Pro:24.04:LTS: freerdp2, Ubuntu:25.10: freerdp3</p>
<p>FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0,  the gdi_surface_bits() function processes SURFACE_BITS_COMMAND messages sent by the RDP server. When the command is handled using NSCodec, the bmp.width and bmp.height values provided by the server are not properly validated against the actual desktop dimensions. A malicious RDP server can supply crafted bmp.width and bmp.height values that exceed the expected surface size. Because these values are used during bitmap decoding and memory operations without proper bounds checking, this can lead to a heap buffer overflow. Since the attacker can also control the associated pixel data transmitted by the server, the overflow may be exploitable to overwrite adjacent heap memory. This vulnerability is fixed in 3.24.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-31806"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0725</id>
    <title>WID-SEC-W-2026-0725 — FreeRDP: Mehrere Schwachstellen</title>
    <updated>2026-10-03T16:26:46.705906+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in FreeRDP ausnutzen, um potenziell beliebigen Code auszuführen, einen Denial-of-Service-Zustand herbeizuführen, Speicherbeschädigungen zu verursachen, Daten zu manipulieren oder vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0725"/>
  </entry>
</feed>
