[CLSA-2026:1789731393] freerdp: Fix of 4 CVEs
Type:
security
Severity:
None
Release date:
2026-09-18 11:36:41 UTC
Description:
- Rebase onto vendor freerdp-2.11.7-1.amzn2.0.15, which fixes CVE-2026-63652 - CVE-2026-25959: retained TuxCare fix; lock the cliprdr cache when providing data, closing the use-after-free between the cliprdr channel thread and the X11 event thread in xf_cliprdr - CVE-2026-67288: retained TuxCare fix completing the vendor's backport, which left "data" uninitialised in PCSC_SCardReadCacheA() and the HashTable lookup in PCSC_SCardReadCacheW() unguarded against a NULL szLookupName key - CVE-2026-67301: complete the fix. Guarding the point allocation with numPoints > 0 left wParam->points, copied from the parser's own struct, aliasing polygon_{sc,cb}->points when numPoints is zero -- and update_message_free_update_class() frees it unconditionally, so the async consumer freed memory the parser still owns. Set it to NULL on that branch
Updated packages:
  • freerdp-2.11.7-1.amzn2.0.15.tuxcare.els1.x86_64.rpm
    sha:b15419e48b47edffd0283e24e90d5180361be2e68ba07882c6faadcf7b5e54c3
  • freerdp-devel-2.11.7-1.amzn2.0.15.tuxcare.els1.x86_64.rpm
    sha:28f79b7c5e1adfa04e41204bae8c96eb27c6ce317bd0d657afb4759cf3cf162a
  • freerdp-libs-2.11.7-1.amzn2.0.15.tuxcare.els1.i686.rpm
    sha:6bbbeb263d2166b7997ee6c1ab9536ce35a02f21533e3b664aa776f21fb01335
  • freerdp-libs-2.11.7-1.amzn2.0.15.tuxcare.els1.x86_64.rpm
    sha:7589cc8231e2dd6f43172396227c24284e72173ef3fe0df44a1989ed7709325c
  • libwinpr-2.11.7-1.amzn2.0.15.tuxcare.els1.i686.rpm
    sha:f077c0243a6b6a78ab37108d2a82a03d5aaafdf9ce196b41096c0c6d2c75141c
  • libwinpr-2.11.7-1.amzn2.0.15.tuxcare.els1.x86_64.rpm
    sha:dd5414bbcc8cdda8ea469476bf4069abe13948a66f630c4a8fd70e460d326695
  • libwinpr-devel-2.11.7-1.amzn2.0.15.tuxcare.els1.x86_64.rpm
    sha:aa8ed870ae7335b7f73632f8cdc003848bef2ea37f068527b1e4fe6839ec34ff
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.