Re: [BLFS Trac] #23257: FreeRDP-3.26.0

"BLFS Trac" ([email protected] via blfs-book Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.beyond.book
Message-ID <[email protected]>
#23257: FreeRDP-3.26.0
-------------------------+-------------------------------
 Reporter:  Bruce Dubbs  |       Owner:  SecurityAdvisory
     Type:  enhancement  |      Status:  new
 Priority:  high         |   Milestone:  13.1
Component:  BOOK         |     Version:  git
 Severity:  normal       |  Resolution:
 Keywords:               |
-------------------------+-------------------------------
Comment (by Douglas R. Reno):

 - CVE-2026-44420 (8.8 High): FreeRDP cliprdr server heap-buffer-overflow
 via undersized capabilitySetLength in CB_CLIP_CAPS. RCE and DoS
 - CVE-2026-45700 (8.8 High): Heap-buffer-overflow write in planar bitmap
 decoder. RCE and DoS
 - https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-p6r2-4hgm-
 m6ff - "
 FreeRDP RDPGFX CacheToSurface heap-buffer-overflow via clamped-rectangle
 validation bypass"... no CVE assigned, but 8.8 High rating assigned. DoS
 and possible RCE.
 - https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-j9q5-7g8m-
 jc9v - "FreeRDP RDPEAR NDR ref-id aliasing causes client-side UAF/double-
 free and type confusion"... 7.5 High rating assigned, no CVE assigned.
 Type confusion causing possible RCE, but primary impact is DoS.
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23257#comment:4>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.