[Git][security-tracker-team/security-tracker][master] Add oss-security reference for freerdp3 issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Sep 5 06:15:55 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
1b5bc6c2 by Salvatore Bonaccorso at 2026-09-05T07:15:11+02:00
Add oss-security reference for freerdp3 issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1175,24 +1175,29 @@ CVE-2026-XXXX [FreeRDP server DRDYNVC parser use-after-free during concurrent ch
- freerdp3 3.31.0+dfsg-1
- freerdp2 <removed>
NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-6mpx-c8rj-whj5
+ NOTE: https://www.openwall.com/lists/oss-security/2026/09/01/2
CVE-2026-XXXX [FreeRDP RDPGFX ResetGraphics discloses up to 300 bytes of uninitialized heap memory]
- freerdp3 3.31.0+dfsg-1
- freerdp2 <removed>
NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-r7jx-j9h7-j4xj
+ NOTE: https://www.openwall.com/lists/oss-security/2026/09/01/2
CVE-2026-XXXX [Smartcard response lengths are not bounded to their inline ATR arrays]
- freerdp3 3.31.0+dfsg-1
[trixie] - freerdp3 <not-affected> (Only affects 3.28 and later)
- freerdp2 <not-affected> (Only affects 3.28 and later)
NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-q65v-4w7q-hx3r
+ NOTE: https://www.openwall.com/lists/oss-security/2026/09/01/2
CVE-2026-XXXX [SHOW_PROTOCOL live-pointer overwrite]
- freerdp3 3.31.0+dfsg-1
[trixie] - freerdp3 <not-affected> (Only affects 3.28 and later)
- freerdp2 <not-affected> (Only affects 3.28 and later)
NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-9jcm-x588-gh26
+ NOTE: https://www.openwall.com/lists/oss-security/2026/09/01/2
CVE-2026-XXXX [FreeRDP server continues after negotiation failure and dispatches a failure code as RDSTLS]
- freerdp3 3.31.0+dfsg-1
- freerdp2 <not-affected> (Only affects 3.0 and later)
NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-x7v6-xfx3-52j6
+ NOTE: https://www.openwall.com/lists/oss-security/2026/09/01/2
CVE-2026-XXXX [RDPDR out-of-bounds read in rdpdr_dump_packet via UINT32 wraparound in 16 + computerNameLen guard]
- freerdp3 3.31.0+dfsg-1
- freerdp2 <removed>
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1b5bc6c23abf1dc415677fec7359a8fbc56e6efe
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1b5bc6c23abf1dc415677fec7359a8fbc56e6efe
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260905/b76fbec7/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list