Linuxsecurity
Critical FreeRDP Vulnerabilities in Ubuntu 25.10 and 24.04 LTS
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Multiple vulnerabilities were discovered in FreeRDP, affecting Ubuntu 25.10 and 24.04 LTS. The flaws allow remote attackers to exploit improperly handled RDP packets, potentially leading to denial of service or arbitrary code execution. Affected CVEs include CVE-2026-22851 through CVE-2026-27951, with several published between January 14 and February 25, 2026. Users are advised to update their systems to the latest package versions to mitigate these vulnerabilities. The specific package versions required are libfreerdp3-3 3.16.0+dfsg-2ubuntu0.3 for Ubuntu 25.10 and libfreerdp3-3 3.5.1+dfsg1-0ubuntu1.4 for Ubuntu 24.04 LTS. A standard system update will apply the necessary changes. The vulnerabilities pose a significant risk due to the potential for remote exploitation.
Key Points: • FreeRDP vulnerabilities allow remote denial of service and arbitrary code execution. • Affected systems include Ubuntu 25.10 and 24.04 LTS with specific package versions to update. • Multiple CVEs were published between January and February 2026, indicating a serious issue.