Amazon Linux 2023 Security Advisory: ALAS2023-2026-2053
Advisory Released Date: 2026-08-17
Advisory Updated Date: 2026-08-17
FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypto/crypto.c). The function writes the modular-exponentiation result into the caller's output buffer via BN_bn2bin() and only afterward checks output_length > out_length, so out-of-bounds bytes are written before the bounds check. On the server side, when a client selects RDP Standard Security, the encrypted client random is decrypted into a fixed 32-byte buffer. Because the server publishes its RSA public key, an unauthenticated attacker can forge a ciphertext whose decrypted value is up to the full modulus length (e.g. 256 bytes for RSA-2048), overflowing the 32-byte heap buffer by up to ~224 attacker-controlled bytes pre-authentication, resulting in denial of service. (CVE-2026-64620)
FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double-free vulnerability in freerdp_client_rdp_file_apply_to_settings() (client/common/file.c) when parsing the selectedmonitors field of a .rdp connection file. The MonitorIds array is allocated through the settings object, and a raw non-owning pointer to it is freed on the strtoul error path without clearing settings->MonitorIds, leaving it dangling; at teardown freerdp_settings_free() frees the same buffer again. An attacker who convinces a victim to open a crafted .rdp file with oversized monitor tokens can trigger a size-controlled double-free in any FreeRDP CLI client (xfreerdp/sdl-freerdp/wlfreerdp) in the default configuration. (CVE-2026-64621)
Affected Packages:
freerdp
Issue Correction:
Run dnf update freerdp --releasever 2023.12.20260817 or dnf update --advisory ALAS2023-2026-2053 --releasever 2023.12.20260817 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation
aarch64:
freerdp-libs-debuginfo-3.6.3-1.amzn2023.0.14.aarch64
freerdp-server-debuginfo-3.6.3-1.amzn2023.0.14.aarch64
libwinpr-devel-3.6.3-1.amzn2023.0.14.aarch64
freerdp-server-3.6.3-1.amzn2023.0.14.aarch64
libwinpr-debuginfo-3.6.3-1.amzn2023.0.14.aarch64
freerdp-debuginfo-3.6.3-1.amzn2023.0.14.aarch64
libwinpr-3.6.3-1.amzn2023.0.14.aarch64
freerdp-3.6.3-1.amzn2023.0.14.aarch64
freerdp-libs-3.6.3-1.amzn2023.0.14.aarch64
freerdp-devel-3.6.3-1.amzn2023.0.14.aarch64
freerdp-debugsource-3.6.3-1.amzn2023.0.14.aarch64
src:
freerdp-3.6.3-1.amzn2023.0.14.src
x86_64:
libwinpr-devel-3.6.3-1.amzn2023.0.14.x86_64
freerdp-3.6.3-1.amzn2023.0.14.x86_64
freerdp-server-debuginfo-3.6.3-1.amzn2023.0.14.x86_64
freerdp-server-3.6.3-1.amzn2023.0.14.x86_64
freerdp-debuginfo-3.6.3-1.amzn2023.0.14.x86_64
libwinpr-debuginfo-3.6.3-1.amzn2023.0.14.x86_64
freerdp-libs-3.6.3-1.amzn2023.0.14.x86_64
freerdp-devel-3.6.3-1.amzn2023.0.14.x86_64
libwinpr-3.6.3-1.amzn2023.0.14.x86_64
freerdp-debugsource-3.6.3-1.amzn2023.0.14.x86_64
freerdp-libs-debuginfo-3.6.3-1.amzn2023.0.14.x86_64