Explore top 10 tips to secure your open-source projects now. Read More
×
Update to 3.30.0 Update to 3.29.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-fa672d26a8 2026-07-21 01:13:08.976727+00:00 -------------------------------------------------------------------------------- Name : freerdp Product : Fedora 43 Version : 3.30.0 Release : 1.fc43 URL : http://www.freerdp.com/ Summary : Free implementation of the Remote Desktop Protocol (RDP) Description : The xfreerdp & wlfreerdp Remote Desktop Protocol (RDP) clients from the FreeRDP project. xfreerdp & wlfreerdp can connect to RDP servers such as Microsoft Windows machines, xrdp and VirtualBox. -------------------------------------------------------------------------------- Update Information: Update to 3.30.0 Update to 3.29.0 -------------------------------------------------------------------------------- ChangeLog: * Thu Jul 16 2026 Ondrej Holy - 2:3.30.0-1 - Update to 3.30.0 Resolves: rhbz#2501274 * Wed Jul 15 2026 Fedora Release Engineering - 2:3.29.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild * Wed Jul 15 2026 Ondrej Holy - 2:3.29.0-1 - Update to 3.29.0 Resolves: rhbz#2499994 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2499994 - freerdp-3.29.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2499994 [ 2 ] Bug #2501274 - freerdp-3.30.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2501274 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-fa672d26a8' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used bythe Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Release notes for xrdp v0.10.6.1 (2026/07/06) General announcements This release fixes 10 vulnerabilities and 1 regression introduced by a vulnerability fix in the previous release. If you like xrdp, please consider sponsoring or donating to the project. We. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-bd0a75766f 2026-07-16 01:28:35.510767+00:00 -------------------------------------------------------------------------------- Name : xrdp Product : Fedora 43 Version : 0.10.6.1 Release : 1.fc43 URL : http://www.xrdp.org/ Summary : Open source remote desktop protocol (RDP) server Description : xrdp provides a fully functional RDP server compatible with a wide range of RDP clients, including FreeRDP and Microsoft RDP client. -------------------------------------------------------------------------------- Update Information: Release notes for xrdp v0.10.6.1 (2026/07/06) General announcements This release fixes 10 vulnerabilities and 1 regression introduced by a vulnerability fix in the previous release. If you like xrdp, please consider sponsoring or donating to the project. We accept financial contributions through Open Collective, and direct donations to individual developers via GitHub Sponsors are also welcome. Security fixes CVE-2026-41252 CVE-2026-41521 CVE-2026-44178 CVE-2026-42218 CVE-2026-44978 CVE-2026-54538 CVE-2026-55238 CVE-2026-55626 CVE-2026-55639 CVE-2026-55645 New features None Bug fixes regression: Fix SEGV in xrdp when running over TLS (#3793) -------------------------------------------------------------------------------- ChangeLog: * Tue Jul 7 2026 Bojan Smojver - 1:0.10.6.1-1 - Update to 0.10.6.1 - CVE-2026-41252, CVE-2026-41521, CVE-2026-44178, CVE-2026-42218 - CVE-2026-44978, CVE-2026-54538, CVE-2026-55238, CVE-2026-55626 - CVE-2026-55639, CVE-2026-55645 * Sat Jun 13 2026 Yaakov Selkowitz - 1:0.10.6-3 - Rebuilt for openssl4.0 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-bd0a75766f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 3.27.1 It fixes CVE-2026-55191, CVE-2026-55192, CVE-2026-55193, CVE-2026-55194, CVE-2026-55648 and CVE-2026-55827.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-78a12ffec8 2026-07-04 01:06:18.979228+00:00 -------------------------------------------------------------------------------- Name : freerdp Product : Fedora 43 Version : 3.27.1 Release : 1.fc43 URL : http://www.freerdp.com/ Summary : Free implementation of the Remote Desktop Protocol (RDP) Description : The xfreerdp & wlfreerdp Remote Desktop Protocol (RDP) clients from the FreeRDP project. xfreerdp & wlfreerdp can connect to RDP servers such as Microsoft Windows machines, xrdp and VirtualBox. -------------------------------------------------------------------------------- Update Information: Update to 3.27.1 It fixes CVE-2026-55191, CVE-2026-55192, CVE-2026-55193, CVE-2026-55194, CVE-2026-55648 and CVE-2026-55827. -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 18 2026 Ondrej Holy - 2:3.27.1-1 - Update to 3.27.1 (CVE-2026-55191, CVE-2026-55192, CVE-2026-55193, CVE-2026-55194, CVE-2026-55648, CVE-2026-55827) Resolves: rhbz#2488900 * Fri Jun 12 2026 Yaakov Selkowitz - 2:3.26.0-8 - Rebuilt for openssl 4.0 * Mon Jun 8 2026 František Zatloukal - 2:3.26.0-7 - Rebuilt for icu 78.3 * Thu Jun 4 2026 Ondrej Holy - 2:3.26.0-6 - Enable uriparser support on RHEL * Tue May 26 2026 Yaakov Selkowitz - 2:3.26.0-5 - Drop multilib-rpm-config usage on RHEL -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-78a12ffec8' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More detailson the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Critical updates for FreeRDP address multiple exploits, ensuring Fedora 43 users are secured against potential threats.. Fedora security patch, FreeRDP update, remote desktop vulnerability, Fedora 43 security. . Severity: Critical. LinuxSecurity.com Team
Update to 3.27.1 It fixes CVE-2026-55191, CVE-2026-55192, CVE-2026-55193, CVE-2026-55194, CVE-2026-55648 and CVE-2026-55827.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-9c6082d92d 2026-06-22 00:50:54.985280+00:00 -------------------------------------------------------------------------------- Name : freerdp Product : Fedora 44 Version : 3.27.1 Release : 1.fc44 URL : http://www.freerdp.com/ Summary : Free implementation of the Remote Desktop Protocol (RDP) Description : The xfreerdp & wlfreerdp Remote Desktop Protocol (RDP) clients from the FreeRDP project. xfreerdp & wlfreerdp can connect to RDP servers such as Microsoft Windows machines, xrdp and VirtualBox. -------------------------------------------------------------------------------- Update Information: Update to 3.27.1 It fixes CVE-2026-55191, CVE-2026-55192, CVE-2026-55193, CVE-2026-55194, CVE-2026-55648 and CVE-2026-55827. -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 18 2026 Ondrej Holy - 2:3.27.1-1 - Update to 3.27.1 (CVE-2026-55191, CVE-2026-55192, CVE-2026-55193, CVE-2026-55194, CVE-2026-55648, CVE-2026-55827) Resolves: rhbz#2488900 * Fri Jun 12 2026 Yaakov Selkowitz - 2:3.26.0-8 - Rebuilt for openssl 4.0 * Mon Jun 8 2026 František Zatloukal - 2:3.26.0-7 - Rebuilt for icu 78.3 * Thu Jun 4 2026 Ondrej Holy - 2:3.26.0-6 - Enable uriparser support on RHEL * Tue May 26 2026 Yaakov Selkowitz - 2:3.26.0-5 - Drop multilib-rpm-config usage on RHEL -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-9c6082d92d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More detailson the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Critical updates for Fedora 44 FreeRDP addressing multiple CVEs. Ensure your system security with the latest patches.. Fedora security updates, FreeRDP patch, Fedora CVE fixes, Remote Desktop Protocol security. . Severity: Important. LinuxSecurity.com Team
Close TCP socket in default configuration, because we want just Unix domain socket connections to Xvnc.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-8aeca78af9 2026-05-30 01:07:34.273962+00:00 -------------------------------------------------------------------------------- Name : xrdp Product : Fedora 43 Version : 0.10.6 Release : 2.fc43 URL : http://www.xrdp.org/ Summary : Open source remote desktop protocol (RDP) server Description : xrdp provides a fully functional RDP server compatible with a wide range of RDP clients, including FreeRDP and Microsoft RDP client. -------------------------------------------------------------------------------- Update Information: Close TCP socket in default configuration, because we want just Unix domain socket connections to Xvnc. -------------------------------------------------------------------------------- ChangeLog: * Fri May 22 2026 Bojan Smojver - 1:0.10.6-2 - close TCP port in default Xvnc config, Unix domain socket only -------------------------------------------------------------------------------- References: [ 1 ] Bug #2480423 - no authentication required to connect to Xvnc https://bugzilla.redhat.com/show_bug.cgi?id=2480423 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-8aeca78af9' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list--
Close TCP socket in default configuration, because we want just Unix domain socket connections to Xvnc.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-9a3a98bc24 2026-05-30 00:54:46.011421+00:00 -------------------------------------------------------------------------------- Name : xrdp Product : Fedora 44 Version : 0.10.6 Release : 2.fc44 URL : http://www.xrdp.org/ Summary : Open source remote desktop protocol (RDP) server Description : xrdp provides a fully functional RDP server compatible with a wide range of RDP clients, including FreeRDP and Microsoft RDP client. -------------------------------------------------------------------------------- Update Information: Close TCP socket in default configuration, because we want just Unix domain socket connections to Xvnc. -------------------------------------------------------------------------------- ChangeLog: * Fri May 22 2026 Bojan Smojver - 1:0.10.6-2 - close TCP port in default Xvnc config, Unix domain socket only -------------------------------------------------------------------------------- References: [ 1 ] Bug #2480423 - no authentication required to connect to Xvnc https://bugzilla.redhat.com/show_bug.cgi?id=2480423 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-9a3a98bc24' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list--
Update to 3.26.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-dfde5fc92a 2026-05-15 03:06:23.642321+00:00 -------------------------------------------------------------------------------- Name : freerdp Product : Fedora 43 Version : 3.26.0 Release : 4.fc43 URL : http://www.freerdp.com/ Summary : Free implementation of the Remote Desktop Protocol (RDP) Description : The xfreerdp & wlfreerdp Remote Desktop Protocol (RDP) clients from the FreeRDP project. xfreerdp & wlfreerdp can connect to RDP servers such as Microsoft Windows machines, xrdp and VirtualBox. -------------------------------------------------------------------------------- Update Information: Update to 3.26.0 -------------------------------------------------------------------------------- ChangeLog: * Sun May 10 2026 Neal Gompa - 2:3.26.0-4 - Enable WebAuthN/FIDO2 passthrough support * Sun May 10 2026 Shawn W Dunn - 2:3.26.0-3 - Drop 0001-add-sso-mib-dependency-to-client-cmake.patch * Sun May 10 2026 Shawn W Dunn - 2:3.26.0-2 - Add 0001-add-sso-mib-dependency-to-client-cmake.patch * Thu May 7 2026 Ondrej Holy - 2:3.26.0-1 - Update to 3.26.0 Resolves: rhbz#2467244 * Tue Apr 28 2026 Yaakov Selkowitz - 2:3.25.0-2 - Disable AOM AV1 support on RHEL * Thu Apr 23 2026 Neal Gompa - 2:3.25.0-1 - Update to 3.25.0 (CVE-2026-40254) Resolves: rhbz#2461094 - Enable AV1 support * Sat Apr 4 2026 Luca Boccassi - 2:3.24.2-2 - Build with sso-mib support -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-dfde5fc92a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPGkeys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Security fixes CVE-2026-32105 CVE-2026-32107 CVE-2026-32623 CVE-2026-32624. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-9417ff0bc5 2026-04-28 00:55:52.209245+00:00 -------------------------------------------------------------------------------- Name : xrdp Product : Fedora 43 Version : 0.10.6 Release : 1.fc43 URL : http://www.xrdp.org/ Summary : Open source remote desktop protocol (RDP) server Description : xrdp provides a fully functional RDP server compatible with a wide range of RDP clients, including FreeRDP and Microsoft RDP client. -------------------------------------------------------------------------------- Update Information: Security fixes CVE-2026-32105 CVE-2026-32107 CVE-2026-32623 CVE-2026-32624 CVE-2026-33145 CVE-2026-33516 CVE-2026-33689 CVE-2026-35512 New features Support for xorgxrdp bug fixes #249 and #342 (#3721) Bug fixes Honour pass_shell_as_env setting only if user sets a shell (#3725) We no longer try to create a NULL authentication file when using VNC over UDS (#3727) Problems with the Brazilian ABNT2 keyboard mapping have been corrected (#3728 3736) A 'file exists' error when installing xrdp over an existing installation has been addressed (#3780) -------------------------------------------------------------------------------- ChangeLog: * Sat Apr 18 2026 Bojan Smojver - 1:0.10.6-1 - Update to 0.10.6 - CVE-2026-32105, CVE-2026-32107, CVE-2026-32623, CVE-2026-32624 - CVE-2026-33145, CVE-2026-33516, CVE-2026-33689, CVE-2026-35512 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2459298 - CVE-2026-32105 xrdp: xrdp: Data integrity compromised due to missing MAC signature verification in Classic RDP Security [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2459298 [ 2 ] Bug #2459302 - CVE-2026-32107 xrdp: xrdp: Privilege Escalation via improper privilegemanagement [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2459302 [ 3 ] Bug #2459616 - CVE-2026-33145 xrdp: xrdp: Arbitrary Command Execution via unsafe handling of AlternateShell parameter [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2459616 [ 4 ] Bug #2459618 - CVE-2026-32623 xrdp: xrdp NeutrinoRDP: Remote Code Execution or Denial of Service via heap-based buffer overflow in fragmented RDP data handling [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2459618 [ 5 ] Bug #2459620 - CVE-2026-35512 xrdp: xrdp: Remote Code Execution via heap-based buffer overflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2459620 [ 6 ] Bug #2459621 - CVE-2026-33516 xrdp: xrdp: Denial of Service and Information Disclosure via specially crafted RDP message [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2459621 [ 7 ] Bug #2459623 - CVE-2026-33689 xrdp: xrdp: Denial of Service and Information Disclosure via Out-of-Bounds Read [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2459623 [ 8 ] Bug #2459625 - CVE-2026-32624 xrdp: xrdp: Denial of Service via crafted username and domain name [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2459625 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-9417ff0bc5' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.