Bugs fixes in "freerdp3"
| Origin | Bug number | Title | Date fixed |
|---|---|---|---|
| CVE | CVE-2026-23533 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the RDPGFX Cle | 2026-03-18 |
| CVE | CVE-2026-23532 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the FreeRDP c | 2026-03-18 |
| CVE | CVE-2026-23531 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, in ClearCodec, when `glyphData` is present, `clear_decompre | 2026-03-18 |
| CVE | CVE-2026-23530 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0,`freerdp_bitmap_decompress_planar` does not validate `nSrcWi | 2026-03-18 |
| CVE | CVE-2026-22859 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, the URBDRC client does not perform bounds checking on server‑suppli | 2026-03-18 |
| CVE | CVE-2026-22858 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, global-buffer-overflow was observed in FreeRDP's Base64 decoding pa | 2026-03-18 |
| CVE | CVE-2026-22857 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap use-after-free occurs in irp_thread_func because the IRP is | 2026-03-18 |
| CVE | CVE-2026-22856 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race in the serial channel IRP thread tracking allows a heap use‑ | 2026-03-18 |
| CVE | CVE-2026-22855 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap out-of-bounds read occurs in the smartcard SetAttrib path wh | 2026-03-18 |
| CVE | CVE-2026-22854 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap-buffer-overflow occurs in drive read when a server-controlle | 2026-03-18 |
| CVE | CVE-2026-22852 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a malicious RDP server can trigger a heap-buffer-overflow write in | 2026-03-18 |
| CVE | CVE-2026-22851 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race condition between the RDPGFX dynamic virtual channel thread | 2026-03-18 |
| CVE | CVE-2026-24684 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, the RDPSND async playback thread can process queued PDUs after the | 2026-02-16 |
| CVE | CVE-2026-24683 | FreeRDP is a free implementation of the Remote Desktop Protocol. ainput_send_input_event caches channel_callback in a local variable and later uses i | 2026-02-16 |
| CVE | CVE-2026-24681 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, aAsynchronous bulk transfer completions can use a freed channel cal | 2026-02-16 |
| CVE | CVE-2026-24680 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, sdl_Pointer_New frees data on failure, then pointer_free calls sdl_ | 2026-02-16 |
| CVE | CVE-2026-24676 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, AUDIN format renegotiation frees the active format list while the c | 2026-02-16 |
| CVE | CVE-2026-24682 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, audin_server_recv_formats frees an incorrect number of audio format | 2026-02-16 |
| CVE | CVE-2026-24679 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, The URBDRC client uses server-supplied interface numbers as array i | 2026-02-16 |
| CVE | CVE-2026-24675 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, urb_select_interface can free the device's MS config on error but l | 2026-02-16 |
About
-
Send Feedback to @ubuntu_updates