Re: [BLFS Trac] #23257: FreeRDP-3.26.0
| Newsgroups | gmane.linux.lfs.beyond.book |
|---|---|
| Message-ID | <[email protected]> |
#23257: FreeRDP-3.26.0
-------------------------+-------------------------------
Reporter: Bruce Dubbs | Owner: SecurityAdvisory
Type: enhancement | Status: new
Priority: high | Milestone: 13.1
Component: BOOK | Version: git
Severity: normal | Resolution:
Keywords: |
-------------------------+-------------------------------
Comment (by Douglas R. Reno):
- CVE-2026-44420 (8.8 High): FreeRDP cliprdr server heap-buffer-overflow
via undersized capabilitySetLength in CB_CLIP_CAPS. RCE and DoS
- CVE-2026-45700 (8.8 High): Heap-buffer-overflow write in planar bitmap
decoder. RCE and DoS
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-p6r2-4hgm-
m6ff - "
FreeRDP RDPGFX CacheToSurface heap-buffer-overflow via clamped-rectangle
validation bypass"... no CVE assigned, but 8.8 High rating assigned. DoS
and possible RCE.
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-j9q5-7g8m-
jc9v - "FreeRDP RDPEAR NDR ref-id aliasing causes client-side UAF/double-
free and type confusion"... 7.5 High rating assigned, no CVE assigned.
Type confusion causing possible RCE, but primary impact is DoS.
--
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23257#comment:4>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch
--
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page