SUSE-SU-2026:3562-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20263562-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3562-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:3562-1
Upstream
CVE (20)
Related
Published
2026-08-10T18:16:39Z
Modified
2026-08-12T10:45:04Z
Summary
Security update for freerdp
Details

This update for freerdp fixes the following issues:

  • CVE-2026-27951: 32-bit system denial of service via endless blocking loop in Stream_EnsureCapacity (bsc#1258939).
  • CVE-2026-33952: client denial of service via unvalidated authentication length field (bsc#1261196).
  • CVE-2026-33977: client denial of service via malformed IMA ADPCM audio data (bsc#1261198).
  • CVE-2026-33982: heap buffer overread in winpr_aligned_offset_recalloc() can lead to undefined behavior (bsc#1261222).
  • CVE-2026-33983: improper error handling can lead to use of incorrect shift exponent, undefined behavior and an 80 billion iteration loop (bsc#1261200).
  • CVE-2026-33984: heap buffer overflow allows arbitrary code execution via crafted pixel data (bsc#1261211).
  • CVE-2026-33985: heap out-of-bounds read can leak sensitive data when pixel data is rendered to screen (bsc#1261217).
  • CVE-2026-33986: heap out-of-bounds write due to H.264 YUV buffer dimension desync (bsc#1261223).
  • CVE-2026-33987: heap out-of-bounds write due to persistent cache bmpSize desync (bsc#1261226).
  • CVE-2026-33995: double-free in kerberos_AcceptSecurityContext() and kerberos_InitializeSecurityContextA() can lead to crash during NLA connection teardown with a failed authentication attempt (bsc#1261227).
  • CVE-2026-40033: heap buffer overflow in gdi_CacheToSurface allows attackers to cause a denial of service or achieve remote code execution (bsc#1266317).
  • CVE-2026-40254: off-by-one error in contains_dotdot() allows for drive channel path traversal (bsc#1262743).
  • CVE-2026-44420: heap buffer overwrite can be triggered in server-side clipboard channel when a malicious client sends a CB_CLIP_CAPS PDU with a too-small capabilitySetLength (bsc#1267008).
  • CVE-2026-44421: improper validation in gdi_CacheToSurface can lead to a heap buffer overwrite client when an RDP server sends crafted RDPGFX PDUs (bsc#1267009).
  • CVE-2026-44422: improper memory management can lead to heap use-after-free/double-free in a client's RDPEAR authentication-redirection path (bsc#1267010).
  • CVE-2026-45700: data check bypass when decoding RLE planar data can lead to an out-of-bounds heap write (bsc#1267011).
  • CVE-2026-56297: improper synchronization of channel_callback access can lead to use-after-free in dvcman_channel_close and dvcman_call_on_receive triggered by a malicious RDP server (bsc#1271071).
  • CVE-2026-57156: integer overflow in update_read_delta_points allows malicious RDP peers to cause a heap buffer overflow (bsc#1271303).
  • CVE-2026-57157: 2-byte heap out-of-bounds read via attacker-supplied MS-RDPECAM DeviceName and VirtualChannelName fields (bsc#1271304).
  • CVE-2026-57158: incomplete fix for CVE-2026-23530 in planar_decompress_plane_rle_only allows a malicious RDP server to trigger a one byte buffer overflow via a truncated RDPGFX_CMDID_WIRETOSURFACE_1 planar payload (bsc#1271305).
References

Affected packages

SUSE:Linux Enterprise Module for Package Hub 15 SP7
freerdp

Package

Name
freerdp
Purl
pkg:rpm/suse/freerdp&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.10.3-150700.3.17.1

Ecosystem specific

{
    "binaries":  [
        {
            "freerdp":  "3.10.3-150700.3.17.1",
            "freerdp-devel":  "3.10.3-150700.3.17.1",
            "freerdp-proxy":  "3.10.3-150700.3.17.1",
            "freerdp-server":  "3.10.3-150700.3.17.1",
            "freerdp-wayland":  "3.10.3-150700.3.17.1",
            "libuwac0-0":  "3.10.3-150700.3.17.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3562-1.json"
SUSE:Linux Enterprise Workstation Extension 15 SP7
freerdp

Package

Name
freerdp
Purl
pkg:rpm/suse/freerdp&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.10.3-150700.3.17.1

Ecosystem specific

{
    "binaries":  [
        {
            "freerdp":  "3.10.3-150700.3.17.1",
            "freerdp-devel":  "3.10.3-150700.3.17.1",
            "freerdp-proxy":  "3.10.3-150700.3.17.1",
            "freerdp-proxy-plugins":  "3.10.3-150700.3.17.1",
            "freerdp-sdl":  "3.10.3-150700.3.17.1",
            "freerdp-server":  "3.10.3-150700.3.17.1",
            "libfreerdp-server-proxy3-3":  "3.10.3-150700.3.17.1",
            "libfreerdp3-3":  "3.10.3-150700.3.17.1",
            "librdtk0-0":  "3.10.3-150700.3.17.1",
            "libwinpr3-3":  "3.10.3-150700.3.17.1",
            "winpr-devel":  "3.10.3-150700.3.17.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3562-1.json"