Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 442
Alerts This Week
Warning Icon 1 442

SUSE freerdp2 Important Buffer Overflow Denial of Service Advis 2026-1640-1

suse
Calendar Grey April 28, 2026
Scroller Suse
Critical update for freerdp2 on SUSE fixes multiple issues, including Denial of Service and buffer overflow risks. Install soon.
An update that solves 15 vulnerabilities and has one security fix can now be installed.

Summary

## This update for freerdp2 fixes the following issues: * CVE-2026-25941: Out-of-Bounds Read in client RDPGFX channel via crafted `WIRE_TO_SURFACE_2` PDU (bsc#1258919). * CVE-2026-25942: Global-buffer-overflow in `xf_rail_server_execute_result` (bsc#1258920). * CVE-2026-25952: Heap-use-after-free in `xf_SetWindowMinMaxInfo` (bsc#1258921). * CVE-2026-25953: Heap-use-after-free in `xf_AppUpdateWindowFromSurface` (bsc#1258923). * CVE-2026-25954: Heap-use-after-free in `xf_rail_server_local_move_size` (bsc#1258924). * CVE-2026-25997: Heap-use-after-free in `xf_clipboard_format_equal` (bsc#1258977). * CVE-2026-26986: Heap-use-after-free in `rail_window_free` (bsc#1258967). * CVE-2026-27015: Smartcard NDR alignment padding triggers reachable

References

* bsc#1258919

* bsc#1258920

* bsc#1258921

* bsc#1258923

* bsc#1258924

* bsc#1258939

* bsc#1258967

* bsc#1258977

* bsc#1258987

* bsc#1259653

* bsc#1259680

* bsc#1259684

* bsc#1259689

* bsc#1259692

* bsc#1259693

* bsc#1261848

Cross-

* CVE-2026-25941

* CVE-2026-25942

* CVE-2026-25952

* CVE-2026-25953

* CVE-2026-25954

* CVE-2026-25997

* CVE-2026-26986

* CVE-2026-27015

* CVE-2026-27951

* CVE-2026-29774

* CVE-2026-29775

* CVE-2026-29776

* CVE-2026-31806

* CVE-2026-31884

* CVE-2026-31897

CVSS scores:

* CVE-2026-25941 ( SUSE ): 5.1

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

* CVE-2026-25941 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

* CVE-2026-25941 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:1640-1
Release Date: 2026-04-28T11:33:59Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.