[Git][security-tracker-team/security-tracker][master] Add oss-security reference for freerdp3 issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 5 06:15:55 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1b5bc6c2 by Salvatore Bonaccorso at 2026-09-05T07:15:11+02:00
Add oss-security reference for freerdp3 issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1175,24 +1175,29 @@ CVE-2026-XXXX [FreeRDP server DRDYNVC parser use-after-free during concurrent ch
 	- freerdp3 3.31.0+dfsg-1
 	- freerdp2 <removed>
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-6mpx-c8rj-whj5
+	NOTE: https://www.openwall.com/lists/oss-security/2026/09/01/2
 CVE-2026-XXXX [FreeRDP RDPGFX ResetGraphics discloses up to 300 bytes of uninitialized heap memory]
 	- freerdp3 3.31.0+dfsg-1
 	- freerdp2 <removed>
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-r7jx-j9h7-j4xj
+	NOTE: https://www.openwall.com/lists/oss-security/2026/09/01/2
 CVE-2026-XXXX [Smartcard response lengths are not bounded to their inline ATR arrays]
 	- freerdp3 3.31.0+dfsg-1
 	[trixie] - freerdp3 <not-affected> (Only affects 3.28 and later)
 	- freerdp2 <not-affected> (Only affects 3.28 and later)
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-q65v-4w7q-hx3r
+	NOTE: https://www.openwall.com/lists/oss-security/2026/09/01/2
 CVE-2026-XXXX [SHOW_PROTOCOL live-pointer overwrite]
 	- freerdp3 3.31.0+dfsg-1
 	[trixie] - freerdp3 <not-affected> (Only affects 3.28 and later)
 	- freerdp2 <not-affected> (Only affects 3.28 and later)
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-9jcm-x588-gh26
+	NOTE: https://www.openwall.com/lists/oss-security/2026/09/01/2
 CVE-2026-XXXX [FreeRDP server continues after negotiation failure and dispatches a failure code as RDSTLS]
 	- freerdp3 3.31.0+dfsg-1
 	- freerdp2 <not-affected> (Only affects 3.0 and later)
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-x7v6-xfx3-52j6
+	NOTE: https://www.openwall.com/lists/oss-security/2026/09/01/2
 CVE-2026-XXXX [RDPDR out-of-bounds read in rdpdr_dump_packet via UINT32 wraparound in 16 + computerNameLen guard]
 	- freerdp3 3.31.0+dfsg-1
 	- freerdp2 <removed>



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1b5bc6c23abf1dc415677fec7359a8fbc56e6efe

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1b5bc6c23abf1dc415677fec7359a8fbc56e6efe
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260905/b76fbec7/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list