## This update for freerdp fixes the following issues: * CVE-2026-25941: Out-of-Bounds Read in client RDPGFX channel via crafted `WIRE_TO_SURFACE_2` PDU (bsc#1258919). * CVE-2026-25942: Global-buffer-overflow in `xf_rail_server_execute_result` (bsc#1258920). * CVE-2026-25952: Heap-use-after-free in `xf_SetWindowMinMaxInfo` (bsc#1258921). * CVE-2026-25953: Heap-use-after-free in `xf_AppUpdateWindowFromSurface` (bsc#1258923). * CVE-2026-25954: Heap-use-after-free in `xf_rail_server_local_move_size` (bsc#1258924). * CVE-2026-25955: Heap-use-after-free in `xf_AppUpdateWindowFromSurface` (bsc#1258973). * CVE-2026-25959: Heap-use-after-free in `xf_cliprdr_provide_data_` (bsc#1258976). * CVE-2026-25997: Heap-use-after-free in `xf_clipboard_format_equal`
* bsc#1258919
* bsc#1258920
* bsc#1258921
* bsc#1258923
* bsc#1258924
* bsc#1258939
* bsc#1258941
* bsc#1258967
* bsc#1258973
* bsc#1258976
* bsc#1258977
* bsc#1258987
* bsc#1259680
* bsc#1259684
* bsc#1259689
* bsc#1259692
* bsc#1259693
* jsc#PED-13439
Cross-
* CVE-2026-25941
* CVE-2026-25942
* CVE-2026-25952
* CVE-2026-25953
* CVE-2026-25954
* CVE-2026-25955
* CVE-2026-25959
* CVE-2026-25997
* CVE-2026-26986
* CVE-2026-27015
* CVE-2026-27950
* CVE-2026-27951
* CVE-2026-29774
* CVE-2026-29775
* CVE-2026-29776
* CVE-2026-31884
* CVE-2026-31897
CVSS scores:
* CVE-2026-25941 ( SUSE ): 5.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-25941 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Get the latest Linux and open source security news straight to your inbox.