[Git][security-tracker-team/security-tracker][master] More FreeRDP issues CVEified

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Sep 15 21:02:27 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
49ea7059 by Salvatore Bonaccorso at 2026-09-15T22:00:17+02:00
More FreeRDP issues CVEified

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -81,34 +81,6 @@ CVE-2026-91966 (AVideo through 29.0 contains an unauthenticated server-side requ
 	NOT-FOR-US: WWBN AVideo
 CVE-2026-91965 (WWBN AVideo through 29.0 fails to enforce user-group restrictions in t ...)
 	NOT-FOR-US: WWBN AVideo
-CVE-2026-91958 (FreeRDP versions before 3.31.0 fail to validate MonitorIds array value ...)
-	TODO: check
-CVE-2026-91957 (FreeRDP before 3.31.0 contains a use-after-free vulnerability in the s ...)
-	TODO: check
-CVE-2026-91956 (FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in  ...)
-	TODO: check
-CVE-2026-91955 (FreeRDP before 3.31.0 fails to validate client-supplied DesktopWidth a ...)
-	TODO: check
-CVE-2026-91954 (FreeRDP before 3.31.0 contains a null pointer dereference vulnerabilit ...)
-	TODO: check
-CVE-2026-91953 (FreeRDP versions before 3.31.0 contain a heap buffer overflow vulnerab ...)
-	TODO: check
-CVE-2026-91952 (FreeRDP versions before 3.31.0 contain an infinite-loop denial of serv ...)
-	TODO: check
-CVE-2026-91951 (FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerab ...)
-	TODO: check
-CVE-2026-91950 (FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in  ...)
-	TODO: check
-CVE-2026-91949 (FreeRDP server versions before 3.31.0 contain a protocol negotiation b ...)
-	TODO: check
-CVE-2026-91948 (FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerab ...)
-	TODO: check
-CVE-2026-91947 (FreeRDP server versions before 3.31.0 contain a use-after-free vulnera ...)
-	TODO: check
-CVE-2026-91946 (FreeRDP versions before 3.31.0 contain an information disclosure vulne ...)
-	TODO: check
-CVE-2026-91945 (FreeRDP versions before 3.31.0 contain an out-of-bounds read vulnerabi ...)
-	TODO: check
 CVE-2026-91944 (crawl4ai versions before 0.9.3 contain a DOM-based cross-site scriptin ...)
 	NOT-FOR-US: crawl4ai
 CVE-2026-91943 (Crawl4AI before 0.9.3 contains a server-side request forgery vulnerabi ...)
@@ -14278,58 +14250,58 @@ CVE-2026-85091 (zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overfl
 	- zlib <unfixed> (bug #1146895)
 	NOTE: https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490
 	NOTE: https://github.com/madler/zlib/issues/1310
-CVE-2026-XXXX [GHSA-6mpx-c8rj-whj5: FreeRDP server DRDYNVC parser use-after-free during concurrent channel close]
+CVE-2026-91947 [GHSA-6mpx-c8rj-whj5: FreeRDP server DRDYNVC parser use-after-free during concurrent channel close]
 	- freerdp3 3.31.0+dfsg-1
 	- freerdp2 <removed>
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-6mpx-c8rj-whj5
 	NOTE: https://www.openwall.com/lists/oss-security/2026/09/01/2
-CVE-2026-XXXX [GHSA-r7jx-j9h7-j4xj: FreeRDP RDPGFX ResetGraphics discloses up to 300 bytes of uninitialized heap memory]
+CVE-2026-91946 [GHSA-r7jx-j9h7-j4xj: FreeRDP RDPGFX ResetGraphics discloses up to 300 bytes of uninitialized heap memory]
 	- freerdp3 3.31.0+dfsg-1
 	- freerdp2 <removed>
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-r7jx-j9h7-j4xj
 	NOTE: https://www.openwall.com/lists/oss-security/2026/09/01/2
-CVE-2026-XXXX [GHSA-q65v-4w7q-hx3r: Smartcard response lengths are not bounded to their inline ATR arrays]
+CVE-2026-91945 [GHSA-q65v-4w7q-hx3r: Smartcard response lengths are not bounded to their inline ATR arrays]
 	- freerdp3 3.31.0+dfsg-1
 	[trixie] - freerdp3 <not-affected> (Only affects 3.28 and later)
 	- freerdp2 <not-affected> (Only affects 3.28 and later)
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-q65v-4w7q-hx3r
 	NOTE: https://www.openwall.com/lists/oss-security/2026/09/01/2
-CVE-2026-XXXX [GHSA-9jcm-x588-gh26: SHOW_PROTOCOL live-pointer overwrite]
+CVE-2026-91948 [GHSA-9jcm-x588-gh26: SHOW_PROTOCOL live-pointer overwrite]
 	- freerdp3 3.31.0+dfsg-1
 	[trixie] - freerdp3 <not-affected> (Only affects 3.28 and later)
 	- freerdp2 <not-affected> (Only affects 3.28 and later)
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-9jcm-x588-gh26
 	NOTE: https://www.openwall.com/lists/oss-security/2026/09/01/2
-CVE-2026-XXXX [GHSA-x7v6-xfx3-52j6: FreeRDP server continues after negotiation failure and dispatches a failure code as RDSTLS]
+CVE-2026-91949 [GHSA-x7v6-xfx3-52j6: FreeRDP server continues after negotiation failure and dispatches a failure code as RDSTLS]
 	- freerdp3 3.31.0+dfsg-1
 	- freerdp2 <not-affected> (Only affects 3.0 and later)
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-x7v6-xfx3-52j6
 	NOTE: https://www.openwall.com/lists/oss-security/2026/09/01/2
-CVE-2026-XXXX [GHSA-c5gr-hmqp-pwj4: RDPDR out-of-bounds read in rdpdr_dump_packet via UINT32 wraparound in 16 + computerNameLen guard]
+CVE-2026-91950 [GHSA-c5gr-hmqp-pwj4: RDPDR out-of-bounds read in rdpdr_dump_packet via UINT32 wraparound in 16 + computerNameLen guard]
 	- freerdp3 3.31.0+dfsg-1
 	- freerdp2 <removed>
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-c5gr-hmqp-pwj4
-CVE-2026-XXXX [GHSA-h5w2-q35j-443h: Out-of-bounds write in urb_send_current_frame_number_result]
+CVE-2026-91951 [GHSA-h5w2-q35j-443h: Out-of-bounds write in urb_send_current_frame_number_result]
 	- freerdp3 3.31.0+dfsg-1
 	- freerdp2 <not-affected> (Only affects 3.14 and later)
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-h5w2-q35j-443h
-CVE-2026-XXXX [GHSA-m85m-3qxv-63h5: Infinite loop / CPU DoS in pool_decode_rect]
+CVE-2026-91952 [GHSA-m85m-3qxv-63h5: Infinite loop / CPU DoS in pool_decode_rect]
 	- freerdp3 3.31.0+dfsg-1
 	- freerdp2 <not-affected> (Only affects 3.11 and later)
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-m85m-3qxv-63h5
-CVE-2026-XXXX [GHSA-r9pv-ffph-6gg6: Heap buffer overflow in nego_send_negotiation_request via oversized LB_LOAD_BALANCE_INFO routing token]
+CVE-2026-91953 [GHSA-r9pv-ffph-6gg6: Heap buffer overflow in nego_send_negotiation_request via oversized LB_LOAD_BALANCE_INFO routing token]
 	- freerdp3 3.31.0+dfsg-1
 	- freerdp2 <removed>
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-r9pv-ffph-6gg6
-CVE-2026-XXXX [GHSA-ffjr-p229-hpch: NULL pointer dereference in gdi_surface_bits when the client has not enabled NSCodec]
+CVE-2026-91954 [GHSA-ffjr-p229-hpch: NULL pointer dereference in gdi_surface_bits when the client has not enabled NSCodec]
 	- freerdp3 3.31.0+dfsg-1
 	- freerdp2 <removed>
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-ffjr-p229-hpch
-CVE-2026-XXXX [GHSA-4464-r7qj-pgrx: FreeRDP: server stores client Core Data DesktopWidth/Height unvalidated in GCC negotiation]
+CVE-2026-91955 [GHSA-4464-r7qj-pgrx: FreeRDP: server stores client Core Data DesktopWidth/Height unvalidated in GCC negotiation]
 	- freerdp3 3.31.0+dfsg-1
 	- freerdp2 <removed>
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-4464-r7qj-pgrx
-CVE-2026-XXXX [GHSA-hg4r-vv53-vwf8: URBDRC out-of-bounds read in func_get_ep_desc via InterfaceNumber/array-position index mismatch]
+CVE-2026-91956 [GHSA-hg4r-vv53-vwf8: URBDRC out-of-bounds read in func_get_ep_desc via InterfaceNumber/array-position index mismatch]
 	- freerdp3 3.31.0+dfsg-1
 	- freerdp2 <removed>
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-hg4r-vv53-vwf8
@@ -14341,11 +14313,11 @@ CVE-2026-XXXX [GHSA-v649-94v2-p72q: Uninitialised heap disclosure in FreeRDP Sav
 	- freerdp3 3.31.0+dfsg-1
 	- freerdp2 <removed>
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-v649-94v2-p72q
-CVE-2026-XXXX [GHSA-j5mq-3349-gwmm: channels,smartcard worker creation failure frees a devman-owned device]
+CVE-2026-91957 [GHSA-j5mq-3349-gwmm: channels,smartcard worker creation failure frees a devman-owned device]
 	- freerdp3 3.31.0+dfsg-1
 	- freerdp2 <removed>
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-j5mq-3349-gwmm
-CVE-2026-XXXX [GHSA-23pf-q83q-x45r: Unbounded MonitorIds used as an array index in X11 monitor selection]
+CVE-2026-91958 [GHSA-23pf-q83q-x45r: Unbounded MonitorIds used as an array index in X11 monitor selection]
 	- freerdp3 3.31.0+dfsg-1
 	- freerdp2 <not-affected> (Only affects 3.11 and later)
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-23pf-q83q-x45r



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/49ea7059efce91a0040a74b03574ea9f2273053a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/49ea7059efce91a0040a74b03574ea9f2273053a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260915/fcc27ed5/attachment.htm>


More information about the debian-security-tracker-commits mailing list