{"id":"RHSA-2026:76747","summary":"Red Hat Security Advisory: freerdp security update","modified":"2026-10-07T10:31:00.452051610Z","published":"2026-10-07T10:20:09Z","upstream":["CVE-2026-91953","CVE-2026-91954","CVE-2026-91956","CVE-2026-91959","CVE-2026-91963","CVE-2026-91964"],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:76747"},{"type":"ARTICLE","url":"https://access.redhat.com/security/updates/classification/#important"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533906"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533911"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533927"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533930"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533951"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533959"},{"type":"ADVISORY","url":"https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_76747.json"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-91953"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-91953"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91953"},{"type":"ARTICLE","url":"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-r9pv-ffph-6gg6"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/freerdp-before-3.31.0-heap-buffer-overflow-via-lb-load-balance-info"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-91954"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-91954"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91954"},{"type":"ARTICLE","url":"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-ffjr-p229-hpch"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/freerdp-before-3.31.0-null-pointer-dereference-via-nscodec"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-91956"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-91956"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91956"},{"type":"ARTICLE","url":"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-hg4r-vv53-vwf8"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/freerdp-before-3.31.0-out-of-bounds-read-via-urbdrc"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-91959"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-91959"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91959"},{"type":"ARTICLE","url":"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-pj8w-fh79-f438"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/freerdp-before-3.31.0-buffer-over-read-via-rts-gateway"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-91963"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-91963"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91963"},{"type":"ARTICLE","url":"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-hw7p-5h2r-83gq"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/freerdp-2.0.0-through-3.30.0-uninitialized-heap-memory-disclosure-via-urbdrc"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-91964"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-91964"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91964"},{"type":"ARTICLE","url":"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-2vf2-grvj-6g8x"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/freerdp-2.0.0-through-3.30.0-heap-buffer-overflow-via-routingtoken"}],"affected":[{"package":{"name":"freerdp","ecosystem":"Red Hat:enterprise_linux:8::appstream","purl":"pkg:rpm/redhat/freerdp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:2.11.7-14.el8_10"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:76747.json"}},{"package":{"name":"freerdp-debuginfo","ecosystem":"Red Hat:enterprise_linux:8::appstream","purl":"pkg:rpm/redhat/freerdp-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:2.11.7-14.el8_10"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:76747.json"}},{"package":{"name":"freerdp-debugsource","ecosystem":"Red Hat:enterprise_linux:8::appstream","purl":"pkg:rpm/redhat/freerdp-debugsource"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:2.11.7-14.el8_10"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:76747.json"}},{"package":{"name":"freerdp-libs","ecosystem":"Red Hat:enterprise_linux:8::appstream","purl":"pkg:rpm/redhat/freerdp-libs"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:2.11.7-14.el8_10"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:76747.json"}},{"package":{"name":"freerdp-libs-debuginfo","ecosystem":"Red Hat:enterprise_linux:8::appstream","purl":"pkg:rpm/redhat/freerdp-libs-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:2.11.7-14.el8_10"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:76747.json"}},{"package":{"name":"libwinpr","ecosystem":"Red Hat:enterprise_linux:8::appstream","purl":"pkg:rpm/redhat/libwinpr"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:2.11.7-14.el8_10"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:76747.json"}},{"package":{"name":"libwinpr-debuginfo","ecosystem":"Red Hat:enterprise_linux:8::appstream","purl":"pkg:rpm/redhat/libwinpr-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:2.11.7-14.el8_10"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:76747.json"}},{"package":{"name":"libwinpr-devel","ecosystem":"Red Hat:enterprise_linux:8::appstream","purl":"pkg:rpm/redhat/libwinpr-devel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:2.11.7-14.el8_10"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:76747.json"}},{"package":{"name":"freerdp-debuginfo","ecosystem":"Red Hat:enterprise_linux:8::crb","purl":"pkg:rpm/redhat/freerdp-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:2.11.7-14.el8_10"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:76747.json"}},{"package":{"name":"freerdp-debugsource","ecosystem":"Red Hat:enterprise_linux:8::crb","purl":"pkg:rpm/redhat/freerdp-debugsource"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:2.11.7-14.el8_10"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:76747.json"}},{"package":{"name":"freerdp-devel","ecosystem":"Red Hat:enterprise_linux:8::crb","purl":"pkg:rpm/redhat/freerdp-devel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:2.11.7-14.el8_10"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:76747.json"}},{"package":{"name":"freerdp-libs-debuginfo","ecosystem":"Red Hat:enterprise_linux:8::crb","purl":"pkg:rpm/redhat/freerdp-libs-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:2.11.7-14.el8_10"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:76747.json"}},{"package":{"name":"libwinpr-debuginfo","ecosystem":"Red Hat:enterprise_linux:8::crb","purl":"pkg:rpm/redhat/libwinpr-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:2.11.7-14.el8_10"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:76747.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}