MGASA-2026-0086

Source
https://advisories.mageia.org/MGASA-2026-0086.html
Import Source
https://advisories.mageia.org/MGASA-2026-0086.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2026-0086
Related
Published
2026-04-06T17:35:50Z
Modified
2026-04-06T17:45:06.256780Z
Summary
Updated freerdp packages fix security vulnerabilities
Details

FreeRDP has a heap-buffer-overflow in audinprocessformats. (CVE-2026-22852) FreeRDP has a heap-buffer-overflow in driveprocessirpread. (CVE-2026-22854) FreeRDP has a heap-buffer-overflow in smartcardunpacksetattribcall. (CVE-2026-22855) FreeRDP has a heap-use-after-free in createirpthread. (CVE-2026-22856) FreeRDP has a heap-use-after-free in irpthreadfunc. (CVE-2026-22857) FreeRDP has a heap-buffer-overflow in urbselectconfiguration. (CVE-2026-22859) FreeRDP has heap-buffer-overflow in GlyphAlloc. (CVE-2026-23732) Heap-use-after-free in updatepointernew. (CVE-2026-23883) Heap-use-after-free in gdisetbounds. (CVE-2026-23884) FreeRDP has a heap-use-after-free in videotimer. (CVE-2026-24491) Buffer Overread in FreeRDP Icon Processing. (CVE-2026-26271) FreeRDP has Out-of-bounds Write. (CVE-2026-26955, CVE-2026-26965) FreeRDP has a Heap Buffer Overflow in nscprocessmessage() via Unchecked SURFACEBITSCOMMAND Bitmap Dimensions. (CVE-2026-31806) FreeRDP has a size_t underflow in ADPCM decoder leads to heap-buffer-overflow write. (CVE-2026-31883) FreeRDP has an out-of-bounds read in ADPCM decoders due to missing predictor/stepindex bounds checks. (CVE-2026-31885)

References
Credits

Affected packages

Mageia:9 / freerdp

Package

Name
freerdp
Purl
pkg:rpm/mageia/freerdp?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.11.7-1.3.mga9

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0086.json"