Search CVE reports


Toggle filters

1 – 10 of 66 results


CVE-2026-31897

Medium priority
Needs evaluation

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, there is an out-of-bounds read in freerdp_bitmap_decompress_planar when SrcSize is 0. The function dereferences *srcp (which points to pSrcData)...

3 affected packages

freerdp, freerdp2, freerdp3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freerdp Not in release Not in release Needs evaluation
freerdp2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
freerdp3 Needs evaluation Not in release
Show less packages

CVE-2026-31885

Medium priority
Needs evaluation

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, there is an out-of-bounds read in MS-ADPCM and IMA-ADPCM decoders due to unchecked predictor and step_index values from input data....

3 affected packages

freerdp, freerdp2, freerdp3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freerdp Not in release Not in release Needs evaluation
freerdp2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
freerdp3 Needs evaluation Not in release
Show less packages

CVE-2026-31884

Medium priority
Needs evaluation

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, division by zero in MS-ADPCM and IMA-ADPCM decoders when nBlockAlign is 0, leading to a crash. In libfreerdp/codec/dsp.c, both ADPCM decoders use...

3 affected packages

freerdp, freerdp2, freerdp3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freerdp Not in release Not in release Needs evaluation
freerdp2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
freerdp3 Needs evaluation Not in release
Show less packages

CVE-2026-31883

Medium priority
Needs evaluation

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a size_t underflow in the IMA-ADPCM and MS-ADPCM audio decoders leads to heap-buffer-overflow write via the RDPSND audio channel....

3 affected packages

freerdp, freerdp2, freerdp3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freerdp Not in release Not in release Needs evaluation
freerdp2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
freerdp3 Needs evaluation Not in release
Show less packages

CVE-2026-31806

Medium priority
Needs evaluation

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, the gdi_surface_bits() function processes SURFACE_BITS_COMMAND messages sent by the RDP server. When the command is handled using NSCodec, the...

3 affected packages

freerdp, freerdp2, freerdp3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freerdp Not in release Not in release Needs evaluation
freerdp2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
freerdp3 Needs evaluation Not in release
Show less packages

CVE-2026-29776

Medium priority
Needs evaluation

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, Integer Underflow in update_read_cache_bitmap_order Function of FreeRDP's Core Library This vulnerability is fixed in 3.24.0.

3 affected packages

freerdp, freerdp2, freerdp3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freerdp Not in release Not in release Needs evaluation
freerdp2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
freerdp3 Needs evaluation Not in release
Show less packages

CVE-2026-29775

Medium priority
Needs evaluation

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a client-side heap out-of-bounds read/write occurs in FreeRDP's bitmap cache subsystem due to an off-by-one boundary check in bitmap_cache_put. A...

3 affected packages

freerdp, freerdp2, freerdp3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freerdp Not in release Not in release Needs evaluation
freerdp2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
freerdp3 Needs evaluation Not in release
Show less packages

CVE-2026-29774

Medium priority
Needs evaluation

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a client-side heap buffer overflow occurs in the FreeRDP client's AVC420/AVC444 YUV-to-RGB conversion path due to missing horizontal...

3 affected packages

freerdp, freerdp2, freerdp3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freerdp Not in release Not in release Needs evaluation
freerdp2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
freerdp3 Needs evaluation Not in release
Show less packages

CVE-2026-27951

Medium priority
Vulnerable

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, the function `Stream_EnsureCapacity` can create an endless blocking loop. This may affect all client and server implementations...

3 affected packages

freerdp, freerdp2, freerdp3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freerdp Not in release Not in release Needs evaluation
freerdp2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
freerdp3 Vulnerable Not in release
Show less packages

CVE-2026-27950

Medium priority

Some fixes available 1 of 8

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, the fix for the heap-use-after-free described in CVE-2026-24680 is incomplete. While the vulnerable execution flow referenced in the...

3 affected packages

freerdp, freerdp2, freerdp3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freerdp Not in release Not in release Needs evaluation
freerdp2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
freerdp3 Fixed Not in release
Show less packages