{
  "schema_version": "1.7.0",
  "id": "RHSA-2026:61378",
  "related": [],
  "upstream": [
    "CVE-2026-55194",
    "CVE-2026-63633",
    "CVE-2026-63652",
    "CVE-2026-67288",
    "CVE-2026-67291",
    "CVE-2026-67296",
    "CVE-2026-67297",
    "CVE-2026-67298",
    "CVE-2026-67301",
    "CVE-2026-67304",
    "CVE-2026-69159",
    "CVE-2026-73241",
    "CVE-2026-73242"
  ],
  "published": "2026-09-01T10:28:23Z",
  "modified": "2026-09-01T10:28:23Z",
  "summary": "Red Hat Security Advisory: freerdp security update",
  "severity": [
    {
      "type": "CVSS_V3",
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
    }
  ],
  "affected": [
    {
      "package": {
        "name": "freerdp",
        "ecosystem": "Red Hat:enterprise_linux:10.2",
        "purl": "pkg:rpm/redhat/freerdp"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2:3.10.3-12.el10_2.10"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "freerdp-debuginfo",
        "ecosystem": "Red Hat:enterprise_linux:10.2",
        "purl": "pkg:rpm/redhat/freerdp-debuginfo"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2:3.10.3-12.el10_2.10"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "freerdp-debugsource",
        "ecosystem": "Red Hat:enterprise_linux:10.2",
        "purl": "pkg:rpm/redhat/freerdp-debugsource"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2:3.10.3-12.el10_2.10"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "freerdp-libs",
        "ecosystem": "Red Hat:enterprise_linux:10.2",
        "purl": "pkg:rpm/redhat/freerdp-libs"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2:3.10.3-12.el10_2.10"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "freerdp-libs-debuginfo",
        "ecosystem": "Red Hat:enterprise_linux:10.2",
        "purl": "pkg:rpm/redhat/freerdp-libs-debuginfo"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2:3.10.3-12.el10_2.10"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "freerdp-server-debuginfo",
        "ecosystem": "Red Hat:enterprise_linux:10.2",
        "purl": "pkg:rpm/redhat/freerdp-server-debuginfo"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2:3.10.3-12.el10_2.10"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "libwinpr",
        "ecosystem": "Red Hat:enterprise_linux:10.2",
        "purl": "pkg:rpm/redhat/libwinpr"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2:3.10.3-12.el10_2.10"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "libwinpr-debuginfo",
        "ecosystem": "Red Hat:enterprise_linux:10.2",
        "purl": "pkg:rpm/redhat/libwinpr-debuginfo"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2:3.10.3-12.el10_2.10"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "freerdp-devel",
        "ecosystem": "Red Hat:enterprise_linux:10.2",
        "purl": "pkg:rpm/redhat/freerdp-devel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2:3.10.3-12.el10_2.10"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "freerdp-server",
        "ecosystem": "Red Hat:enterprise_linux:10.2",
        "purl": "pkg:rpm/redhat/freerdp-server"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2:3.10.3-12.el10_2.10"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "libwinpr-devel",
        "ecosystem": "Red Hat:enterprise_linux:10.2",
        "purl": "pkg:rpm/redhat/libwinpr-devel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2:3.10.3-12.el10_2.10"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://access.redhat.com/errata/RHSA-2026:61378"
    },
    {
      "type": "ARTICLE",
      "url": "https://access.redhat.com/security/updates/classification/#important"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2509986"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2509994"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2510001"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2510010"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2510029"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2510034"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2510041"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2514346"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2514349"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2519822"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2519824"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2519826"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2519828"
    },
    {
      "type": "ADVISORY",
      "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_61378.json"
    },
    {
      "type": "REPORT",
      "url": "https://access.redhat.com/security/cve/CVE-2026-55194"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55194"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55194"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/FreeRDP/FreeRDP/commit/9f2da52c2341cc14a96ad12e69c5b83d0bcd8b5a"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/FreeRDP/FreeRDP/pull/12873"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/FreeRDP/FreeRDP/releases/tag/3.27.0"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-9gxm-3mf5-f5cx"
    },
    {
      "type": "REPORT",
      "url": "https://access.redhat.com/security/cve/CVE-2026-63633"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63633"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63633"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/FreeRDP/FreeRDP/commit/0ed1f95d36913581cf31124f94eb5843d4263eae"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/FreeRDP/FreeRDP/pull/12993"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/FreeRDP/FreeRDP/releases/tag/3.28.0"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-72j9-356v-88xq"
    },
    {
      "type": "REPORT",
      "url": "https://access.redhat.com/security/cve/CVE-2026-63652"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63652"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63652"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/FreeRDP/FreeRDP/commit/caf653c0ba1c75ec8f298d1baa59770102a5d14c"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-9g22-w2gr-vcmp"
    },
    {
      "type": "REPORT",
      "url": "https://access.redhat.com/security/cve/CVE-2026-67288"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67288"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67288"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/FreeRDP/FreeRDP/commit/5370fb26fbf034ecd11d3026b6ad639b5fff493f"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/FreeRDP/FreeRDP/commit/f3b4347105114fe7453828736bea069999af319f"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-ph3q-f9w8-7jf3"
    },
    {
      "type": "ARTICLE",
      "url": "https://www.vulncheck.com/advisories/freerdp-before-denial-of-service-via-smartcard-cache"
    },
    {
      "type": "REPORT",
      "url": "https://access.redhat.com/security/cve/CVE-2026-67291"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67291"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67291"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-hgj8-g595-wfc6"
    },
    {
      "type": "ARTICLE",
      "url": "https://www.vulncheck.com/advisories/freerdp-before-heap-out-of-bounds-read-via-glyph-fragment-add"
    },
    {
      "type": "REPORT",
      "url": "https://access.redhat.com/security/cve/CVE-2026-67296"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67296"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67296"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-jm8r-22j6-4m4v"
    },
    {
      "type": "ARTICLE",
      "url": "https://www.vulncheck.com/advisories/freerdp-before-denial-of-service-via-rdpei-pdu"
    },
    {
      "type": "REPORT",
      "url": "https://access.redhat.com/security/cve/CVE-2026-67297"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67297"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67297"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-2c6r-4pr4-9x8m"
    },
    {
      "type": "ARTICLE",
      "url": "https://www.vulncheck.com/advisories/freerdp-before-resource-exhaustion-via-chunked-http-response"
    },
    {
      "type": "REPORT",
      "url": "https://access.redhat.com/security/cve/CVE-2026-67298"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67298"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67298"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/FreeRDP/FreeRDP/commit/46848765f2a1134f8652f8760eefb5e85d64a9b8"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-qmvw-52ph-q5pv"
    },
    {
      "type": "ARTICLE",
      "url": "https://www.vulncheck.com/advisories/freerdp-heap-buffer-overflow-via-rail-orderlength-underflow"
    },
    {
      "type": "REPORT",
      "url": "https://access.redhat.com/security/cve/CVE-2026-67301"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67301"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67301"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-vxp3-7g6q-rq2w"
    },
    {
      "type": "ARTICLE",
      "url": "https://www.vulncheck.com/advisories/freerdp-before-out-of-bounds-read-via-polygon-async-message-proxy"
    },
    {
      "type": "REPORT",
      "url": "https://access.redhat.com/security/cve/CVE-2026-67304"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67304"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67304"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/FreeRDP/FreeRDP/commit/1cc783d4c78bd2f66d3a8582dfe70a663d141444"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-78jj-45vh-jpm5"
    },
    {
      "type": "ARTICLE",
      "url": "https://www.vulncheck.com/advisories/freerdp-before-null-dereference-via-smartcard-cleanup"
    },
    {
      "type": "REPORT",
      "url": "https://access.redhat.com/security/cve/CVE-2026-69159"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69159"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69159"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/FreeRDP/FreeRDP/commit/75a1ec61d444179ea64a4ec0835214cb9c4f7c18"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/FreeRDP/FreeRDP/pull/13016"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/FreeRDP/FreeRDP/releases/tag/3.29.0"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-qrxx-7g3c-j6w3"
    },
    {
      "type": "REPORT",
      "url": "https://access.redhat.com/security/cve/CVE-2026-73241"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73241"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73241"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/FreeRDP/FreeRDP/commit/b05a9510787c83c87ffc5fa8d7cc9f06ed971695"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/FreeRDP/FreeRDP/pull/13065"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/FreeRDP/FreeRDP/releases/tag/3.30.0"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-rqgv-grx4-xm6x"
    },
    {
      "type": "REPORT",
      "url": "https://access.redhat.com/security/cve/CVE-2026-73242"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73242"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73242"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/FreeRDP/FreeRDP/commit/0adf5e30d01be84e190a359a7bdd37bc51d740cc"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-vv64-95pc-vj9v"
    }
  ]
}