[CLSA-2026:1789724052] freerdp: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-09-19 08:29:09 UTC
Description:
- CVE-2026-91953, CVE-2026-91964: heap buffer overflow in nego_send_negotiation_request(); the server-controlled LB_LOAD_BALANCE_INFO routing token was written into a fixed 512-byte stream with the only length gate running after the write. Add Stream_EnsureRemainingCapacity() guards before every write in the function and fail via the existing cleanup label.
Updated packages:
  • freerdp-2.11.7-1.amzn2.0.15.tuxcare.els2.x86_64.rpm
    sha:6023ffb1d6cd64e1e5ab21bcfbe771d6a7035fb93177f64b41b0e4ad2a9449db
  • freerdp-devel-2.11.7-1.amzn2.0.15.tuxcare.els2.x86_64.rpm
    sha:8a705cca4afec88ce2be23904d78f2267733ef902ee3f6e1e136667baedac3af
  • freerdp-libs-2.11.7-1.amzn2.0.15.tuxcare.els2.i686.rpm
    sha:a7501941c7a60a09d339bcdfeabf3b1924bdeb73e431a48d901b9535e03bd3b9
  • freerdp-libs-2.11.7-1.amzn2.0.15.tuxcare.els2.x86_64.rpm
    sha:e8f1276e1a586007f7228708181a5ab2e94c806fac2a12d0adc5300b19847d8c
  • libwinpr-2.11.7-1.amzn2.0.15.tuxcare.els2.i686.rpm
    sha:b3df7daf43a781b5b15c748f7b2f1cb1aa3806c395581c0e5ef0829fbf347c35
  • libwinpr-2.11.7-1.amzn2.0.15.tuxcare.els2.x86_64.rpm
    sha:95c7293d44867a96d1b15837665db01dd12f29c9f4bc9ccdee7dbdac15dc80d7
  • libwinpr-devel-2.11.7-1.amzn2.0.15.tuxcare.els2.x86_64.rpm
    sha:7f29cc10e7e32d86fb6f0eeaa5f5ff1fc4e5d6be791c90a3a535f33e92531730
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.