The xfreerdp & wlfreerdp Remote Desktop Protocol (RDP) clients from the FreeRDP
project.
xfreerdp & wlfreerdp can connect to RDP servers such as Microsoft Windows
machines, xrdp and VirtualBox.
Update Information:
Update to 3.23.0 to fix CVE-2026-26965, CVE-2026-26955, CVE-2026-26271, CVE-2026-25997, CVE-2026-25959, CVE-2026-25955, CVE-2026-25954, CVE-2026-25953, CVE-2026-25952, CVE-2026-25942, CVE-2026-25941
* Wed Feb 25 2026 Neal Gompa
[ 1 ] Bug #2442856 - CVE-2026-25955 freerdp: FreeRDP: Denial of Service via use-after-free in xf_AppUpdateWindowFromSurface [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2442856
[ 2 ] Bug #2442972 - CVE-2026-26965 freerdp: FreeRDP: Arbitrary code execution via heap out-of-bounds write in RLE planar decode path [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2442972
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-53fe996a57' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
Get the latest Linux and open source security news straight to your inbox.