Release Info

Advisory: CLSA-2026:1771010890

OS: CentOS 7 ELS

Public date: 2026-02-13 19:28:13.944626

Project: freerdp

Version: 2.1.1-5.el7_9.tuxcare.els8

Errata link: https://errata.tuxcare.com/els_os/centos7els/CLSA-2026-1771010890.html

Changelog

- CVE-2026-22859: fix out-of-bounds access due to missing interface index validation in urbdrc channel - CVE-2026-23732: fix out-of-bounds read due to missing input length check in glyph conversion - CVE-2026-23883: fix integer overflow in cursor pixel allocation and surface-to-surface rectangle clamping - CVE-2026-22852: fix heap buffer overflow in audin_process_formats due to stale format count - CVE-2026-23531: fix out-of-bounds read/write in clear_decompress due to missing glyphData bounds check

Update

Update command: yum update freerdp*

Packages list

freerdp-2.1.1-5.el7_9.tuxcare.els8.x86_64.rpm freerdp-devel-2.1.1-5.el7_9.tuxcare.els8.i686.rpm freerdp-devel-2.1.1-5.el7_9.tuxcare.els8.x86_64.rpm freerdp-libs-2.1.1-5.el7_9.tuxcare.els8.i686.rpm freerdp-libs-2.1.1-5.el7_9.tuxcare.els8.x86_64.rpm libwinpr-2.1.1-5.el7_9.tuxcare.els8.i686.rpm libwinpr-2.1.1-5.el7_9.tuxcare.els8.x86_64.rpm libwinpr-devel-2.1.1-5.el7_9.tuxcare.els8.i686.rpm libwinpr-devel-2.1.1-5.el7_9.tuxcare.els8.x86_64.rpm

CVEs

CVE-2026-23883
CVE-2026-23732
CVE-2026-22859
CVE-2026-23531
CVE-2026-22852