[CLSA-2026:1790065872] freerdp: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-09-22 11:21:19 UTC
Description:
- CVE-2026-67291: fix heap out-of-bounds read in update_process_glyph_fragments; reject a GLYPH_FRAGMENT_ADD update whose one-byte server-declared fragment size exceeds the bytes remaining in the received order buffer, instead of passing it straight to glyph_cache_fragment_put which copies that many bytes - CVE-2026-67288: fix NULL pointer dereference in the smartcard cache handlers; card_id_and_name_a now rejects NULL CardIdentifier/LookupName instead of calling strlen on them, and PCSC_SCardReadCacheA/W skip the cache lookup and initialise data, so a NULL NDR LookupName pointer in SCARD_IOCTL_READCACHEA/W can no longer crash the client
Updated packages:
  • freerdp-2.1.1-5.el7_9.tuxcare.els27.x86_64.rpm
    sha:d5d2bec20dfdff56644d40ffef358b2dd0939a09f16664de15511cdf64ec2c1d
  • freerdp-devel-2.1.1-5.el7_9.tuxcare.els27.i686.rpm
    sha:59949b387df6d13a6e726c2af799f8eb31e3f12cf461c15814144ed4dabf353a
  • freerdp-devel-2.1.1-5.el7_9.tuxcare.els27.x86_64.rpm
    sha:34e1c7b3873c43c5cadb1cb929dff8393c9cca8611ccfc792388261eeaca0dd6
  • freerdp-libs-2.1.1-5.el7_9.tuxcare.els27.i686.rpm
    sha:47b3765380d51d7a05cf141da327b1881f572b451690bd3f254b804eb1d85253
  • freerdp-libs-2.1.1-5.el7_9.tuxcare.els27.x86_64.rpm
    sha:4acd2cb18b69d689b7546170259f0e107e3cbdba5493467833f75cf92232fde4
  • libwinpr-2.1.1-5.el7_9.tuxcare.els27.i686.rpm
    sha:86b51900dbe91de4d74d81396f53ccf64f90122fb178e7de5572f3a77bb05399
  • libwinpr-2.1.1-5.el7_9.tuxcare.els27.x86_64.rpm
    sha:4bd9013c2a6fab08fe203653e07f094bf1fa0747a480df7fade64508a71b94e1
  • libwinpr-devel-2.1.1-5.el7_9.tuxcare.els27.i686.rpm
    sha:33598e5c7b23e4449f74a1327c06f9c8edded94b97dd7bf876e67df01bea44ad
  • libwinpr-devel-2.1.1-5.el7_9.tuxcare.els27.x86_64.rpm
    sha:528e5cd4ea25698e04536777e216991f589efc9cd1d157be1c7027a9b581f823
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.