Skip to content
Fedora 44 freerdp2 Update CVE Fixes Denial of Service 2026

Fedora 44 freerdp2 Update CVE Fixes Denial of Service 2026

Linuxsecurity LinuxSecurity Advisories September 10, 2026

Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×

The xfreerdp & wlfreerdp Remote Desktop Protocol (RDP) clients from the FreeRDP

xfreerdp & wlfreerdp can connect to RDP servers such as Microsoft Windows

machines, xrdp and VirtualBox.

Backport several CVE fixes

* Mon Aug 31 2026 Ondrej Holy - 2.11.7-16 - Backport several CVE fixes (CVE-2026-22852, CVE-2026-22854, CVE-2026-22855, CVE-2026-22856, CVE-2026-22858, CVE-2026-22859, CVE-2026-23530, CVE-2026-23531, CVE-2026-23532, CVE-2026-23533, CVE-2026-23534, CVE-2026-23732, CVE-2026-23883, CVE-2026-23884, CVE-2026-23948, CVE-2026-24491, CVE-2026-24675, CVE-2026-24676, CVE-2026-24679, CVE-2026-24681, CVE-2026-24683, CVE-2026-24684, CVE-2026-25952, CVE-2026-26955, CVE-2026-26965, CVE-2026-26986, CVE-2026-27951, CVE-2026-29775, CVE-2026-31806, CVE-2026-31883, CVE-2026-31884, CVE-2026-31885, CVE-2026-33983, CVE-2026-33984, CVE-2026-33985, CVE-2026-45700, CVE-2026-64624, CVE-2026-67289, CVE-2026-67299 and CVE-2026-68580) Resolves: rhbz#2430919, rhbz#2430908, rhbz#2430898, rhbz#2430914, rhbz#2430903 Resolves: rhbz#2430924, rhbz#2430933, rhbz#2429808, rhbz#2429823, rhbz#2429794 Resolves: rhbz#2443146, rhbz#2442975, rhbz#2429799, rhbz#2429814, rhbz#2429821 Resolves: rhbz#2438309, rhbz#2438321, rhbz#2438308, rhbz#2438328, rhbz#2438324 Resolves: rhbz#2438302, rhbz#2438310, rhbz#2438300, rhbz#2447394, rhbz#2453243 Resolves: rhbz#2453240, rhbz#2442837, rhbz#2442810, rhbz#2447426, rhbz#2447422 Resolves: rhbz#2447413, rhbz#2447416, rhbz#2453247, rhbz#2442857, rhbz#2491683 Resolves: rhbz#2510295, rhbz#2510643, rhbz#2503646, rhbz#2510448 * Wed Jul 15 2026 Fedora Release Engineering - 2.11.7-15 - Rebuilt for * Fri Jun 12 2026 Yaakov Selkowitz - 2.11.7-14 - Rebuilt for openssl 4.0 * Mon Jun 8 2026 František Zatloukal - 2.11.7-13 - Rebuilt for icu 78.3 * Thu Apr 16 2026 Cristian Le - 2.11.7-12 - Allow to build with CMake 4.0 (rhbz#2380607)

* Mon Aug 31 2026 Ondrej Holy - 2.11.7-16 - Backport several CVE fixes (CVE-2026-22852, CVE-2026-22854, CVE-2026-22855, CVE-2026-22856, CVE-2026-22858, CVE-2026-22859, CVE-2026-23530, CVE-2026-23531, CVE-2026-23532, CVE-2026-23533, CVE-2026-23534, CVE-2026-23732, CVE-2026-23883, CVE-2026-23884, CVE-2026-23948, CVE-2026-24491, CVE-2026-24675, CVE-2026-24676, CVE-2026-24679, CVE-2026-24681, CVE-2026-24683, CVE-2026-24684, CVE-2026-25952, CVE-2026-26955, CVE-2026-26965, CVE-2026-26986, CVE-2026-27951, CVE-2026-29775, CVE-2026-31806, CVE-2026-31883, CVE-2026-31884, CVE-2026-31885, CVE-2026-33983, CVE-2026-33984, CVE-2026-33985, CVE-2026-45700, CVE-2026-64624, CVE-2026-67289, CVE-2026-67299 and CVE-2026-68580) Resolves: rhbz#2430919, rhbz#2430908, rhbz#2430898, rhbz#2430914, rhbz#2430903 Resolves: rhbz#2430924, rhbz#2430933, rhbz#2429808, rhbz#2429823, rhbz#2429794 Resolves: rhbz#2443146, rhbz#2442975, rhbz#2429799, rhbz#2429814, rhbz#2429821 Resolves: rhbz#2438309, rhbz#2438321, rhbz#2438308, rhbz#2438328, rhbz#2438324 Resolves: rhbz#2438302, rhbz#2438310, rhbz#2438300, rhbz#2447394, rhbz#2453243 Resolves: rhbz#2453240, rhbz#2442837, rhbz#2442810, rhbz#2447426, rhbz#2447422 Resolves: rhbz#2447413, rhbz#2447416, rhbz#2453247, rhbz#2442857, rhbz#2491683 Resolves: rhbz#2510295, rhbz#2510643, rhbz#2503646, rhbz#2510448 * Wed Jul 15 2026 Fedora Release Engineering - 2.11.7-15 - Rebuilt for * Fri Jun 12 2026 Yaakov Selkowitz - 2.11.7-14 - Rebuilt for openssl 4.0 * Mon Jun 8 2026 František Zatloukal - 2.11.7-13 - Rebuilt for icu 78.3 * Thu Apr 16 2026 Cristian Le - 2.11.7-12 - Allow to build with CMake 4.0 (rhbz#2380607)

[ 1 ] Bug #2429794 - Private bug [ 2 ] Bug #2429799 - Private bug [ 3 ] Bug #2429808 - Private bug [ 4 ] Bug #2429814 - Private bug [ 5 ] Bug #2429821 - Private bug [ 6 ] Bug #2429823 - Private bug [ 7 ] Bug #2430898 - CVE-2026-23532 freerdp2: FreeRDP: Denial of Service and potential code execution via client-side heap buffer overflow [fedora-43] [ 8 ] Bug #2430903 - CVE-2026-23534 freerdp2: FreeRDP: Arbitrary code execution and denial of service via client-side heap buffer overflow [fedora-43] ...

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-d91338eea8' at the command line. For more information, refer to the dnf documentation available at

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases