ALAS2-2026-3938


Amazon Linux 2 (EOS) Security Advisory: ALAS2-2026-3938
Advisory Released Date: 2026-09-28
Advisory Updated Date: 2026-09-28
Severity: Important

Issue Overview:

A flaw was found in FreeRDP. This vulnerability allows a remote attacker with low privileges to disclose sensitive information from the server or proxy process memory to a downstream client. This occurs because certain functions responsible for writing Save Session Info Protocol Data Units (PDUs) use Stream_Seek instead of Stream_Zero for reserved padding fields, leading to the transmission of uninitialized heap memory that may contain cleartext credentials from previous sessions. (CVE-2026-85089)

A flaw was found in FreeRDP. A heap out-of-bounds read vulnerability exists in the `general_ChromaV1ToYUV444` function during AVC444 chroma plane reconstruction. A remote attacker, acting as a malicious Remote Desktop Protocol (RDP) server, can exploit this by sending a specially crafted `RFX_AVC444_BITMAP_STREAM` with specific frame geometry. This can lead to an out-of-bounds memory read, potentially disclosing sensitive heap data to the client or causing a client crash, resulting in a denial of service. (CVE-2026-85090)

FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fixed 340-byte wire format. Attackers can receive uninitialized heap memory including live pointers and GLib function addresses transmitted in the PDU, defeating heap ASLR and disclosing the GLib module base address. (CVE-2026-91946)

FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock. Authenticated clients can race AUDIN channel closure messages against DRDYNVC data parsing to trigger heap-use-after-free when accessing freed channel objects. (CVE-2026-91947)

FreeRDP versions before 3.31.0 contain a heap buffer overflow vulnerability in nego_send_negotiation_request() that fails to validate the LB_LOAD_BALANCE_INFO field length before writing to a fixed 512-byte buffer. A malicious RDP server or man-in-the-middle can send a Server Redirection PDU with an oversized LB_LOAD_BALANCE_INFO value to overflow the buffer with attacker-controlled content, causing denial of service or heap corruption before authentication completes. (CVE-2026-91953)

FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the URBDRC channel's func_get_ep_desc function that indexes interface arrays by position instead of protocol field InterfaceNumber. A malicious RDP server can send a crafted SELECT_CONFIGURATION message with permuted InterfaceNumber values to read past allocated heap memory and crash the client. (CVE-2026-91956)

FreeRDP before 3.31.0 contains a use-after-free vulnerability in the smartcard RDPDR device handler when worker thread creation fails after device registration. Attackers can trigger thread creation failure during channel setup to cause device pointer deallocation while devman retains a reference, leading to crash or code execution. (CVE-2026-91957)

FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monitors. Attackers can craft a malicious RDP file with an out-of-range selectedmonitors value to trigger out-of-bounds heap read and write operations when opened in xfreerdp. (CVE-2026-91958)

FreeRDP before 3.31.0 contains a buffer over-read vulnerability in the rts_read_result function within the RPC gateway transport parser. Attackers can send a malicious BIND_ACK PDU with a truncated result entry to trigger an out-of-bounds read causing process abort. (CVE-2026-91959)

FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities. (CVE-2026-91963)

FreeRDP versions before 3.31.0 contain a heap-based buffer overflow in nego_send_negotiation_request when processing Server Redirection PDU messages with attacker-controlled LoadBalanceInfo fields. A malicious RDP server can trigger the overflow by sending an arbitrary-length field that gets written to a fixed 512-byte buffer without validation, causing client crashes or potential code execution when chained with memory disclosure. (CVE-2026-91964)


Affected Packages:

freerdp


Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update freerdp or yum update --advisory ALAS2-2026-3938 to update your system.

New Packages:
aarch64:
    freerdp-2.11.7-1.amzn2.0.16.aarch64
    freerdp-libs-2.11.7-1.amzn2.0.16.aarch64
    freerdp-devel-2.11.7-1.amzn2.0.16.aarch64
    libwinpr-2.11.7-1.amzn2.0.16.aarch64
    libwinpr-devel-2.11.7-1.amzn2.0.16.aarch64
    freerdp-debuginfo-2.11.7-1.amzn2.0.16.aarch64

i686:
    freerdp-2.11.7-1.amzn2.0.16.i686
    freerdp-libs-2.11.7-1.amzn2.0.16.i686
    freerdp-devel-2.11.7-1.amzn2.0.16.i686
    libwinpr-2.11.7-1.amzn2.0.16.i686
    libwinpr-devel-2.11.7-1.amzn2.0.16.i686
    freerdp-debuginfo-2.11.7-1.amzn2.0.16.i686

src:
    freerdp-2.11.7-1.amzn2.0.16.src

x86_64:
    freerdp-2.11.7-1.amzn2.0.16.x86_64
    freerdp-libs-2.11.7-1.amzn2.0.16.x86_64
    freerdp-devel-2.11.7-1.amzn2.0.16.x86_64
    libwinpr-2.11.7-1.amzn2.0.16.x86_64
    libwinpr-devel-2.11.7-1.amzn2.0.16.x86_64
    freerdp-debuginfo-2.11.7-1.amzn2.0.16.x86_64