Release date:
2026-09-14 16:04:31 UTC
Description:
- CVE-2026-67291: fix heap out-of-bounds read in update_process_glyph_fragments; reject a GLYPH_FRAGMENT_ADD update whose one-byte server-declared fragment size exceeds the bytes remaining in the received order buffer, instead of passing it straight to glyph_cache_fragment_put which copies that many bytes
- CVE-2026-67288: fix NULL pointer dereference in the smartcard cache handlers; card_id_and_name_a now rejects NULL CardIdentifier/LookupName instead of calling strlen on them, and PCSC_SCardReadCacheA/W skip the cache lookup and initialise data, so a NULL NDR LookupName pointer in SCARD_IOCTL_READCACHEA/W can no longer crash the client
Updated packages:
-
freerdp-2.1.1-5.el7_9.tuxcare.els27.x86_64.rpm
sha:238a646e7521d642cc863e046c0412884afe8928d46d14cc2542c6312c3c06e6
-
freerdp-devel-2.1.1-5.el7_9.tuxcare.els27.i686.rpm
sha:58fb996ac6eadc4f5e40dc75769880f878e0e4a2014da9c1cae54731446374f8
-
freerdp-devel-2.1.1-5.el7_9.tuxcare.els27.x86_64.rpm
sha:545b242d692e683b552ff3bb5456428ef1d72184bac2b567e7c89c685e33d6b7
-
freerdp-libs-2.1.1-5.el7_9.tuxcare.els27.i686.rpm
sha:5c6e5b71a79eb730e427e0e63f8a42c5a0b3a3734096371a94c3766fa991b34d
-
freerdp-libs-2.1.1-5.el7_9.tuxcare.els27.x86_64.rpm
sha:ae36f6f7cb01fe38c531adc0f79e4428e5454c9197f2d7eb45ec992af6afa3b9
-
libwinpr-2.1.1-5.el7_9.tuxcare.els27.i686.rpm
sha:36af7a9d355a8f61606e8d955048035e3d62f09c78364909ea08271b6ac22f1f
-
libwinpr-2.1.1-5.el7_9.tuxcare.els27.x86_64.rpm
sha:55516ba03aa6162a9a1d4adf7939a0de2c21543088d061a66a0d1091265d7443
-
libwinpr-devel-2.1.1-5.el7_9.tuxcare.els27.i686.rpm
sha:81c9425a025888c273ba8befb75d2324ed6d3a15216645c52d3bcaaefb127a9d
-
libwinpr-devel-2.1.1-5.el7_9.tuxcare.els27.x86_64.rpm
sha:267528331c4af363e6c9747f3ff61098b4252a7caf75e9cd7429a8062aacace5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.