Release date:
2026-09-19 08:29:09 UTC
Description:
- CVE-2026-91953, CVE-2026-91964: heap buffer overflow in
nego_send_negotiation_request(); the server-controlled LB_LOAD_BALANCE_INFO
routing token was written into a fixed 512-byte stream with the only length
gate running after the write. Add Stream_EnsureRemainingCapacity() guards
before every write in the function and fail via the existing cleanup label.
Updated packages:
-
freerdp-2.11.7-1.amzn2.0.15.tuxcare.els2.x86_64.rpm
sha:6023ffb1d6cd64e1e5ab21bcfbe771d6a7035fb93177f64b41b0e4ad2a9449db
-
freerdp-devel-2.11.7-1.amzn2.0.15.tuxcare.els2.x86_64.rpm
sha:8a705cca4afec88ce2be23904d78f2267733ef902ee3f6e1e136667baedac3af
-
freerdp-libs-2.11.7-1.amzn2.0.15.tuxcare.els2.i686.rpm
sha:a7501941c7a60a09d339bcdfeabf3b1924bdeb73e431a48d901b9535e03bd3b9
-
freerdp-libs-2.11.7-1.amzn2.0.15.tuxcare.els2.x86_64.rpm
sha:e8f1276e1a586007f7228708181a5ab2e94c806fac2a12d0adc5300b19847d8c
-
libwinpr-2.11.7-1.amzn2.0.15.tuxcare.els2.i686.rpm
sha:b3df7daf43a781b5b15c748f7b2f1cb1aa3806c395581c0e5ef0829fbf347c35
-
libwinpr-2.11.7-1.amzn2.0.15.tuxcare.els2.x86_64.rpm
sha:95c7293d44867a96d1b15837665db01dd12f29c9f4bc9ccdee7dbdac15dc80d7
-
libwinpr-devel-2.11.7-1.amzn2.0.15.tuxcare.els2.x86_64.rpm
sha:7f29cc10e7e32d86fb6f0eeaa5f5ff1fc4e5d6be791c90a3a535f33e92531730
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.