Red Hat Security Advisory: freerdp security update
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox. Security Fix(es): * FreeRDP: FreeRDP: Remote code execution or denial of service via heap-based buffer overflow (CVE-2026-64620) * FreeRDP: FreeRDP: Double-free vulnerability via crafted .rdp file leading to potential remote code execution (CVE-2026-64621) * FreeRDP: FreeRDP: Arbitrary code execution via malicious RDP files (CVE-2026-64624) * FreeRDP: FreeRDP: Denial of Service via crafted WindowIcon async message (CVE-2026-67299) * FreeRDP: FreeRDP: HTTP Proxy Request Injection via Redirection (CVE-2026-67289) * FreeRDP: FreeRDP: Remote code execution or denial of service via audio input integer overflow (CVE-2026-68580) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
AI Analysis
Technical Summary
FreeRDP, an open-source Remote Desktop Protocol client, contains several security flaws including heap-based buffer overflow (CVE-2026-64620), double-free vulnerability via crafted .rdp files (CVE-2026-64621), arbitrary code execution through malicious RDP files (CVE-2026-64624), denial of service via crafted WindowIcon async messages (CVE-2026-67299), HTTP proxy request injection via redirection (CVE-2026-67289), and remote code execution or denial of service via audio input integer overflow (CVE-2026-68580). These vulnerabilities affect FreeRDP versions prior to 3.30.0+dfsg-0ubuntu0.24.04.1 and 3.30.0+dfsg-0ubuntu0.26.04.1 as packaged in Ubuntu and Red Hat Enterprise Linux 10 distributions. Red Hat and Ubuntu have released security advisories and patches to address these issues, with Red Hat providing updated packages for multiple architectures and Ubuntu providing fixes via standard system updates and Ubuntu Pro Extended Security Maintenance. No known exploits in the wild have been reported at this time.
Potential Impact
The vulnerabilities allow an attacker to potentially execute arbitrary code remotely or cause denial of service conditions on systems running vulnerable versions of FreeRDP. Exploitation could be triggered by crafted RDP files or specially crafted network messages, impacting the confidentiality, integrity, and availability of affected systems. The issues include heap-based buffer overflow, double-free, integer overflow, and HTTP proxy request injection, which collectively represent significant security risks if unpatched.
Mitigation Recommendations
Red Hat has released updated FreeRDP packages for Red Hat Enterprise Linux 10 and related variants that fix these vulnerabilities. Users should apply the security updates provided by Red Hat as detailed in the advisory RHSA-2026:54486. Ubuntu users should update their systems to the patched versions available through standard system updates or Ubuntu Pro Extended Security Maintenance. No additional mitigation steps are indicated beyond applying the official patches.
Red Hat Security Advisory: freerdp security update
Description
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox. Security Fix(es): * FreeRDP: FreeRDP: Remote code execution or denial of service via heap-based buffer overflow (CVE-2026-64620) * FreeRDP: FreeRDP: Double-free vulnerability via crafted .rdp file leading to potential remote code execution (CVE-2026-64621) * FreeRDP: FreeRDP: Arbitrary code execution via malicious RDP files (CVE-2026-64624) * FreeRDP: FreeRDP: Denial of Service via crafted WindowIcon async message (CVE-2026-67299) * FreeRDP: FreeRDP: HTTP Proxy Request Injection via Redirection (CVE-2026-67289) * FreeRDP: FreeRDP: Remote code execution or denial of service via audio input integer overflow (CVE-2026-68580) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected software
pkg:deb/ubuntu/[email protected]~git20140921.1.440916e+dfsg1-5ubuntu1.4?arch=source&distro=xenialpkg:deb/ubuntu/[email protected]+dfsg1-0ubuntu0.18.04.4+esm6?arch=source&distro=esm-infra/bionicpkg:deb/ubuntu/[email protected]~git20140921.1.440916e+dfsg1-15ubuntu1.18.04.2?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]+dfsg1-0ubuntu0.20.04.2+esm4?arch=source&distro=esm-infra/focalpkg:deb/ubuntu/[email protected]+dfsg1-3ubuntu2.11?arch=source&distro=jammypkg:deb/ubuntu/[email protected]+dfsg-0ubuntu0.24.04.2?arch=source&distro=noblepkg:deb/ubuntu/[email protected]+dfsg1-1ubuntu0.1~esm6?arch=source&distro=esm-apps/noblepkg:deb/ubuntu/[email protected]+dfsg-0ubuntu0.26.04.2?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
FreeRDP, an open-source Remote Desktop Protocol client, contains several security flaws including heap-based buffer overflow (CVE-2026-64620), double-free vulnerability via crafted .rdp files (CVE-2026-64621), arbitrary code execution through malicious RDP files (CVE-2026-64624), denial of service via crafted WindowIcon async messages (CVE-2026-67299), HTTP proxy request injection via redirection (CVE-2026-67289), and remote code execution or denial of service via audio input integer overflow (CVE-2026-68580). These vulnerabilities affect FreeRDP versions prior to 3.30.0+dfsg-0ubuntu0.24.04.1 and 3.30.0+dfsg-0ubuntu0.26.04.1 as packaged in Ubuntu and Red Hat Enterprise Linux 10 distributions. Red Hat and Ubuntu have released security advisories and patches to address these issues, with Red Hat providing updated packages for multiple architectures and Ubuntu providing fixes via standard system updates and Ubuntu Pro Extended Security Maintenance. No known exploits in the wild have been reported at this time.
Potential Impact
The vulnerabilities allow an attacker to potentially execute arbitrary code remotely or cause denial of service conditions on systems running vulnerable versions of FreeRDP. Exploitation could be triggered by crafted RDP files or specially crafted network messages, impacting the confidentiality, integrity, and availability of affected systems. The issues include heap-based buffer overflow, double-free, integer overflow, and HTTP proxy request injection, which collectively represent significant security risks if unpatched.
Mitigation Recommendations
Red Hat has released updated FreeRDP packages for Red Hat Enterprise Linux 10 and related variants that fix these vulnerabilities. Users should apply the security updates provided by Red Hat as detailed in the advisory RHSA-2026:54486. Ubuntu users should update their systems to the patched versions available through standard system updates or Ubuntu Pro Extended Security Maintenance. No additional mitigation steps are indicated beyond applying the official patches.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-64620
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:Pro:24.04:LTS","Ubuntu:26.04:LTS"]
- Cvss Version
- 4.0
Threat ID: 6a6978839c2644c7f8df5e74
Added to database: 07/29/2026, 03:50:27 UTC
Last enriched: 08/13/2026, 19:29:13 UTC
Last updated: 09/12/2026, 10:01:32 UTC
Views: 73
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.