ALAS2023-2026-2142


Amazon Linux 2023 Security Advisory: ALAS2023-2026-2142
Advisory Released Date: 2026-09-14
Advisory Updated Date: 2026-09-21
Severity: Important

Issue Overview:

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, an authenticated RDP client can advertise DVI ADPCM with nBlockAlign equal to 8 and nChannels equal to 2 to make the `bs` calculation in rdpsnd_server_select_format in channels/rdpsnd/server/rdpsnd_main.c equal zero. The subsequent out_frames modulo `bs` operation raises SIGFPE and terminates the server-side rdpsnd channel process. This vulnerability fixed in 3.28.0. (CVE-2026-63117)

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, freerdp_dsp_decode_opus in libfreerdp/codec/dsp.c calls Stream_EnsureRemainingCapacity on context->common.buffer even though opus_decode writes decoded PCM into the caller-supplied out stream. A malicious RDP server that negotiates WAVE_FORMAT_OPUS with a client built with WITH_OPUS enabled and WITH_DSP_FFMPEG disabled can make libopus write a large decoded frame beyond the 4096-byte StreamPool_Take destination used by channels/rdpsnd/client/rdpsnd_main.c. This can corrupt the client heap, crash the client, and may permit code execution. This issue is fixed in version 3.28.0. (CVE-2026-63633)

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv_formats in channels/rdpsnd/server/rdpsnd_main.c frees context->client_formats on a malformed Client Audio Formats PDU without clearing the owning pointer or num_client_formats. An authenticated RDP client can trigger an error such as a cbSize larger than the remaining record, leave the dangling pointer in the server context, and cause rdpsnd_server_context_free to free the same allocation again at session teardown. This reliably terminates the server and can create allocator-dependent heap corruption. This issue is fixed in version 3.28.0. (CVE-2026-63652)

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.29.0, planar_decompress_plane_rle and planar_decompress_plane_rle_only in libfreerdp/codec/planar.c verify that a control byte exists but do not verify that the source buffer contains the zero to fifteen raw bytes declared by that control byte. A malicious RDP server can send a truncated planar bitmap or surface update whose final control byte claims additional raw bytes, causing the decoder to read beyond pSrcData while processing a color plane. This can crash the client and may disclose adjacent memory. This issue is fixed in version 3.29.0. (CVE-2026-69159)

A flaw was found in FreeRDP. This vulnerability allows a remote attacker with low privileges to disclose sensitive information from the server or proxy process memory to a downstream client. This occurs because certain functions responsible for writing Save Session Info Protocol Data Units (PDUs) use Stream_Seek instead of Stream_Zero for reserved padding fields, leading to the transmission of uninitialized heap memory that may contain cleartext credentials from previous sessions. (CVE-2026-85089)

A flaw was found in FreeRDP. A heap out-of-bounds read vulnerability exists in the `general_ChromaV1ToYUV444` function during AVC444 chroma plane reconstruction. A remote attacker, acting as a malicious Remote Desktop Protocol (RDP) server, can exploit this by sending a specially crafted `RFX_AVC444_BITMAP_STREAM` with specific frame geometry. This can lead to an out-of-bounds memory read, potentially disclosing sensitive heap data to the client or causing a client crash, resulting in a denial of service. (CVE-2026-85090)

FreeRDP versions before 3.31.0 contain an out-of-bounds read vulnerability in smartcard response decoders that fail to validate ATR length fields against fixed inline arrays. Authenticated RDP clients can send oversized ATR lengths in PAKID_CORE_DEVICE_IOCOMPLETION responses to trigger reads past stack or heap objects, causing process termination. (CVE-2026-91945)

FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fixed 340-byte wire format. Attackers can receive uninitialized heap memory including live pointers and GLib function addresses transmitted in the PDU, defeating heap ASLR and disclosing the GLib module base address. (CVE-2026-91946)

FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock. Authenticated clients can race AUDIN channel closure messages against DRDYNVC data parsing to trigger heap-use-after-free when accessing freed channel objects. (CVE-2026-91947)

FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, receive negotiation failures, then complete TLS handshake and enter RDSTLS to bypass pre-authentication transport restrictions. (CVE-2026-91949)

FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the rdpdr_dump_packet function due to 32-bit unsigned integer wraparound in buffer bounds validation. A malicious RDP server can send a crafted RDPDR packet with computerNameLen set to 0xFFFFFFF0 to bypass bounds checks and trigger memory reads past the packet buffer, causing client crashes or heap disclosure in logs. (CVE-2026-91950)

FreeRDP versions before 3.31.0 contain a heap buffer overflow vulnerability in nego_send_negotiation_request() that fails to validate the LB_LOAD_BALANCE_INFO field length before writing to a fixed 512-byte buffer. A malicious RDP server or man-in-the-middle can send a Server Redirection PDU with an oversized LB_LOAD_BALANCE_INFO value to overflow the buffer with attacker-controlled content, causing denial of service or heap corruption before authentication completes. (CVE-2026-91953)

FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the URBDRC channel's func_get_ep_desc function that indexes interface arrays by position instead of protocol field InterfaceNumber. A malicious RDP server can send a crafted SELECT_CONFIGURATION message with permuted InterfaceNumber values to read past allocated heap memory and crash the client. (CVE-2026-91956)

FreeRDP before 3.31.0 contains a use-after-free vulnerability in the smartcard RDPDR device handler when worker thread creation fails after device registration. Attackers can trigger thread creation failure during channel setup to cause device pointer deallocation while devman retains a reference, leading to crash or code execution. (CVE-2026-91957)

FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monitors. Attackers can craft a malicious RDP file with an out-of-range selectedmonitors value to trigger out-of-bounds heap read and write operations when opened in xfreerdp. (CVE-2026-91958)

FreeRDP before 3.31.0 contains a buffer over-read vulnerability in the rts_read_result function within the RPC gateway transport parser. Attackers can send a malicious BIND_ACK PDU with a truncated result entry to trigger an out-of-bounds read causing process abort. (CVE-2026-91959)

FreeRDP before 3.31.0 contains a denial-of-service vulnerability in the URBDRC control-transfer request path that fails to validate OutputBufferSize before forwarding to the libusb backend. A malicious RDP server can send a control-transfer request with OutputBufferSize set to 65536, triggering a reachable assertion that terminates the client process. (CVE-2026-91961)

FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities. (CVE-2026-91963)

FreeRDP versions before 3.31.0 contain a heap-based buffer overflow in nego_send_negotiation_request when processing Server Redirection PDU messages with attacker-controlled LoadBalanceInfo fields. A malicious RDP server can trigger the overflow by sending an arbitrary-length field that gets written to a fixed 512-byte buffer without validation, causing client crashes or potential code execution when chained with memory disclosure. (CVE-2026-91964)


Affected Packages:

freerdp


Issue Correction:
Run dnf update freerdp --releasever 2023.12.20260914 or dnf update --advisory ALAS2023-2026-2142 --releasever 2023.12.20260914 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation

New Packages:
aarch64:
    freerdp-libs-debuginfo-3.31.0-1.amzn2023.aarch64
    libwinpr-debuginfo-3.31.0-1.amzn2023.aarch64
    freerdp-server-3.31.0-1.amzn2023.aarch64
    freerdp-3.31.0-1.amzn2023.aarch64
    freerdp-debugsource-3.31.0-1.amzn2023.aarch64
    libwinpr-3.31.0-1.amzn2023.aarch64
    freerdp-server-debuginfo-3.31.0-1.amzn2023.aarch64
    libwinpr-devel-3.31.0-1.amzn2023.aarch64
    freerdp-devel-3.31.0-1.amzn2023.aarch64
    freerdp-debuginfo-3.31.0-1.amzn2023.aarch64
    freerdp-libs-3.31.0-1.amzn2023.aarch64

src:
    freerdp-3.31.0-1.amzn2023.src

x86_64:
    freerdp-libs-debuginfo-3.31.0-1.amzn2023.x86_64
    freerdp-server-3.31.0-1.amzn2023.x86_64
    freerdp-server-debuginfo-3.31.0-1.amzn2023.x86_64
    freerdp-debugsource-3.31.0-1.amzn2023.x86_64
    freerdp-debuginfo-3.31.0-1.amzn2023.x86_64
    libwinpr-debuginfo-3.31.0-1.amzn2023.x86_64
    libwinpr-devel-3.31.0-1.amzn2023.x86_64
    libwinpr-3.31.0-1.amzn2023.x86_64
    freerdp-3.31.0-1.amzn2023.x86_64
    freerdp-devel-3.31.0-1.amzn2023.x86_64
    freerdp-libs-3.31.0-1.amzn2023.x86_64

Changelog:

2026-09-21: CVE-2026-91953 was added to this advisory.

2026-09-21: CVE-2026-91949 was added to this advisory.

2026-09-21: CVE-2026-91959 was added to this advisory.

2026-09-21: CVE-2026-91958 was added to this advisory.

2026-09-21: CVE-2026-91950 was added to this advisory.

2026-09-21: CVE-2026-91956 was added to this advisory.

2026-09-21: CVE-2026-91947 was added to this advisory.

2026-09-21: CVE-2026-91946 was added to this advisory.

2026-09-21: CVE-2026-91963 was added to this advisory.

2026-09-21: CVE-2026-91945 was added to this advisory.

2026-09-21: CVE-2026-91957 was added to this advisory.

2026-09-21: CVE-2026-91964 was added to this advisory.

2026-09-21: CVE-2026-91961 was added to this advisory.