openSUSE-SU-2026:20632-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20632-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:20632-1
Upstream
CVE (23)
Related
Published
2026-04-27T13:16:46Z
Modified
2026-04-29T08:01:31Z
Summary
Security update for freerdp2
Details

This update for freerdp2 fixes the following issues:

Changes in freerdp2:

  • Update freerdp-3-macro:

    • Add WINPR_ATTR_MALLOC macro from freerdp 3
  • Security fixes for the following issues:

    • CVE-2026-25941: Fixed a out of bounds read (bsc#1258919)
    • CVE-2026-25942: Fixed a buffer overflow in xf_rail_server_execute_result() (bsc#1258920)
    • CVE-2026-27951: Fixed a denial of service in Stream_EnsureCapacity() (bsc#1258939)
    • CVE-2026-25997: Fixed a use-after-free in xf_clipboard_format_equal() (bsc#1258977)
    • CVE-2026-26986: Fixed a use-after-free in rail_window_free() (bsc#1258967)
    • CVE-2026-27015: Fixed a client denial of service via reachable assert (bsc#1258987)
    • CVE-2026-25952: Fixed a use-after-free in xf_SetWindowMinMaxInfo() (bsc#1258921)
    • CVE-2026-25953: Fixed a use-after-free in xf_AppUpdateWindowFromSurface() (bsc#1258923)
    • CVE-2026-25954: Fixed a use-after-free in xf_rail_server_local_move_size() (bsc#1258924)
    • CVE-2026-24684: Fixed a use-after-free in play_thread() (bsc#1257991).
    • CVE-2026-26271: Fixed a buffer overread in icon processing (bsc#1258979)
    • CVE-2026-26955: Fixed a out of bounds write (bsc#1258982)
    • CVE-2026-26965: Fixed a out of bounds write (bsc#1258985)
    • CVE-2026-31806: Fixed a buffer overflow via improper validation of server messages (bsc#1259653)
    • CVE-2026-31883: Fixed a buffer overflow via crafted audio format and wave data (bsc#1259679)
    • CVE-2026-31885: Fixed a out of bounds read (bsc#1259686)
    • CVE-2026-24491: Fix use-after-free that was accidentally introduced in the backport (bsc#1257981)
    • CVE-2026-22855: Fixed a buffer overflow in smartcard_unpack_set_attrib_call() (bsc#1256721)
    • CVE-2026-22857: Fixed a use-after-free in irp_thread_func() (bsc#1256723)
    • CVE-2026-23533: Fixed a buffer overflow in clear_decompress_residual_data() (bsc#1256943)
    • CVE-2026-23732: Fixed a buffer overflow in Glyph_Alloc() (bsc#1256945)
    • CVE-2026-23883: Fixed a use-after-free (bsc#1256946)
    • CVE-2026-23884: Fixed a use-after-free in gdi_set_bounds (bsc#1256947)
References

Affected packages