[Git][security-tracker-team/security-tracker][master] Add initial batch of CVE ified freerdp3 issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Sep 15 20:53:29 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ddcaa60c by Salvatore Bonaccorso at 2026-09-15T21:52:53+02:00
Add initial batch of CVE ified freerdp3 issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -81,18 +81,6 @@ CVE-2026-91966 (AVideo through 29.0 contains an unauthenticated server-side requ
 	NOT-FOR-US: WWBN AVideo
 CVE-2026-91965 (WWBN AVideo through 29.0 fails to enforce user-group restrictions in t ...)
 	NOT-FOR-US: WWBN AVideo
-CVE-2026-91964 (FreeRDP versions before 3.31.0 contain a heap-based buffer overflow in ...)
-	TODO: check
-CVE-2026-91963 (FreeRDP versions before 3.31.0 contain an uninitialized heap memory di ...)
-	TODO: check
-CVE-2026-91962 (FreeRDP before 3.31.0 contains an integer overflow in the audin Apple  ...)
-	TODO: check
-CVE-2026-91961 (FreeRDP before 3.31.0 contains a denial-of-service vulnerability in th ...)
-	TODO: check
-CVE-2026-91960 (FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's  ...)
-	TODO: check
-CVE-2026-91959 (FreeRDP before 3.31.0 contains a buffer over-read vulnerability in the ...)
-	TODO: check
 CVE-2026-91958 (FreeRDP versions before 3.31.0 fail to validate MonitorIds array value ...)
 	TODO: check
 CVE-2026-91957 (FreeRDP before 3.31.0 contains a use-after-free vulnerability in the s ...)
@@ -14361,28 +14349,28 @@ CVE-2026-XXXX [GHSA-23pf-q83q-x45r: Unbounded MonitorIds used as an array index
 	- freerdp3 3.31.0+dfsg-1
 	- freerdp2 <not-affected> (Only affects 3.11 and later)
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-23pf-q83q-x45r
-CVE-2026-XXXX [GHSA-pj8w-fh79-f438: rts_read_result length-checks 2 bytes and then reads 4]
+CVE-2026-91959 [GHSA-pj8w-fh79-f438: rts_read_result length-checks 2 bytes and then reads 4]
 	- freerdp3 3.31.0+dfsg-1
 	- freerdp2 <removed>
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-pj8w-fh79-f438
-CVE-2026-XXXX [GHSA-vccg-35r5-8jrf: Stream_EnsureCapacity still overflows]
+CVE-2026-91960 [GHSA-vccg-35r5-8jrf: Stream_EnsureCapacity still overflows]
 	- freerdp3 3.31.0+dfsg-1
 	[trixie] - freerdp3 <not-affected> (Incomplete fix for CVE-2026-27951 never backported)
 	- freerdp2 <not-affected> (Incomplete fix for CVE-2026-27951 never backported)
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-vccg-35r5-8jrf
-CVE-2026-XXXX [GHSA-w9qg-g24r-77f6: URBDRC/libusb control-transfer path aborts on reachable OutputBufferSize assertion]
+CVE-2026-91961 [GHSA-w9qg-g24r-77f6: URBDRC/libusb control-transfer path aborts on reachable OutputBufferSize assertion]
 	- freerdp3 3.31.0+dfsg-1
 	- freerdp2 <removed>
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-w9qg-g24r-77f6
-CVE-2026-XXXX [GHSA-f5p6-88mh-59vg: audin Apple backends perform overflow-prone buffer size arithmetic from server-controlled values]
+CVE-2026-91962 [GHSA-f5p6-88mh-59vg: audin Apple backends perform overflow-prone buffer size arithmetic from server-controlled values]
 	- freerdp3 3.31.0+dfsg-1
 	- freerdp2 <removed>
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-f5p6-88mh-59vg
-CVE-2026-XXXX [GHSA-hw7p-5h2r-83gq: Disclosure of uninitialized heap memory in the urbdrc USB redirection path]
+CVE-2026-91963 [GHSA-hw7p-5h2r-83gq: Disclosure of uninitialized heap memory in the urbdrc USB redirection path]
 	- freerdp3 3.31.0+dfsg-1
 	- freerdp2 <removed>
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-hw7p-5h2r-83gq
-CVE-2026-XXXX [GHSA-2vf2-grvj-6g8x: Heap buffer overflow in nego_send_negotiation_request]
+CVE-2026-91964 [GHSA-2vf2-grvj-6g8x: Heap buffer overflow in nego_send_negotiation_request]
 	- freerdp3 3.31.0+dfsg-1
 	- freerdp2 <removed>
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-2vf2-grvj-6g8x



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ddcaa60cd3f9ccc93c11835afe67619f39a91402

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ddcaa60cd3f9ccc93c11835afe67619f39a91402
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260915/4ade53c3/attachment.htm>


More information about the debian-security-tracker-commits mailing list