🛡️ openSUSE-SU-2026:20339-1 — freerdp (CVE-2026-23948 +43 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for freerdp

This update for freerdp fixes the following issues:

Update to version 3.22.0 (jsc#PED-15526):

+ Major bugfix release:

  • Complete overhaul of SDL client
  • Introduction of new WINPR_ATTR_NODISCARD macro wrapping compiler or C language version specific [[nodiscard]] attributes
  • Addition of WINPR_ATTR_NODISCARD to (some) public API functions so usage errors are producing warnings now
  • Add some more stringify functions for logging
  • We've received CVE reports, check

https://github.com/FreeRDP/FreeRDP/security/advisories for more details!

@Keryer reported an issue affecting client and proxy:

  • CVE-2026-23948

@ehdgks0627 did some more fuzzying and found quite a number of client side bugs.

  • CVE-2026-24682
  • CVE-2026-24683
  • CVE-2026-24676
  • CVE-2026-24677
  • CVE-2026-24678
  • CVE-2026-24684
  • CVE-2026-24679
  • CVE-2026-24681
  • CVE-2026-24675
  • CVE-2026-24491
  • CVE-2026-24680
  • Changes from version 3.21.0
  • [core,info] fix missing NULL check (#12157)
  • [gateway,tsg] fix TSG_PACKET_RESPONSE parsing (#12161)
  • Allow querying auth identity with kerberos when running as a server (#12162)
  • Sspi krb heimdal (#12163)
  • Tsg fix idleTimeout parsing (#12167)
  • [channels,smartcard] revert 649f7de (#12166)
  • [crypto] deprecate er and der modules (#12170)
  • [channels,rdpei] lock full update, not only parts (#12175)
  • [winpr,platform] add WINPR_ATTR_NODISCARD macro (#12178)
  • Wlog cleanup (#12179)
  • new stringify functions & touch API defines (#12180)
  • Add support for querying SECPKG_ATTR_PACKAGE_INFO to NTLM and Kerberos (#12171)
  • [channels,video] measure times in ns (#12184)
  • [utils] Nodiscard (#12187)
  • Error handling fixes (#12186)
  • [channels,drdynvc] check pointer before reset (#12189)
  • Winpr api def (#12190)
  • [winpr,platform] drop C23 [[nodiscard]] (#12192)
  • [gdi] add additional checks for a valid rdpGdi (#12194)
  • Sdl3 high dpiv2 (#12173)
  • peer: Disconnect if Logon() returned FALSE (#12196)
  • [channels,rdpecam] fix PROPERTY_DESCRIPTION parsing (#12197)
  • [channel,rdpsnd] only clean up thread before free (#12199)
  • [channels,rdpei] add RDPINPUT_CONTACT_FLAG_UP (#12195)
  • Update to version 3.21.0:

+ Bugfix release with a few new API functions addressing shortcomings with

regard to input data validation.

Thanks to @ehdgks0627 we have fixed the following additional (medium)

client side vulnerabilities:

  • CVE-2026-23530
  • CVE-2026-23531
  • CVE-2026-23532
  • CVE-2026-23533
  • CVE-2026-23534
  • CVE-2026-23732
  • CVE-2026-23883
  • CVE-2026-23884
  • Changes from version 3.20.2
  • [client,sdl] fix monitor resolution (#12142)
  • [codec,progressive] fix progressive_rfx_upgrade_block (#12143)
  • Krb cache fix (#12145)
  • Rdpdr improved checks (#12141)
  • Codec advanced length checks (#12146)
  • Glyph fix length checks (#12151)
  • Wlog printf format string checks (#12150)
  • [warnings,format] fix format string warnings (#12152)
  • Double free fixes (#12153)
  • [clang-tidy] clean up code warnings (#12154)
  • Update to version 3.20.2:

+ Patch release fixing a regression with gateway connections

introduced with 3.20.1

What's Changed

  • Warnings and missing enumeration types (#12137)
  • Changes from version 3.20.1:

+ New years cleanup release. Fixes some issues reported and does

a cleaning sweep to bring down warnings.

Thanks to @ehdgks0627 doing some code review/testing we've

uncovered the following (medium) vulnerabilities:

  • CVE-2026-22851
  • CVE-2026-22852
  • CVE-2026-22853
  • CVE-2026-22854
  • CVE-2026-22855
  • CVE-2026-22856
  • CVE-2026-22857
  • CVE-2026-22858
  • CVE-2026-22859

+ These affect FreeRDP based clients only, with the exception of

CVE-2026-22858 also affecting FreeRDP proxy. FreeRDP based

servers are not affected.

  • Update to version 3.20.0:
  • Mingw fixes (#12070)
  • [crypto,certificate_data] add some hostname sanitation
  • [client,common]: Fix loading of rdpsnd channel
  • [client,sdl] set touch and pen hints
  • Changes from version 3.19.1:
  • [core,transport] improve SSL error logging
  • [utils,helpers] fix freerdp_settings_get_legacy_config_path
  • From stdin and sdl-creds improve
  • [crypto,certificate] sanitize hostnames
  • [channels,drdynvc] propagate error in dynamic channel
  • [CMake] make Mbed-TLS and LibreSSL experimental
  • Json fix
  • rdpecam: send sample only if it's available
  • [channels,rdpecam] allow MJPEG frame skip and direct passthrough
  • [winpr,utils] explicit NULL checks in jansson WINPR_JSON_ParseWithLength
  • Changes from version 3.19.0:
  • [client,common] fix retry counter
  • [cmake] fix aarch64 neon detection
  • Fix response body existence check when using RDP Gateway
  • fix line clipping issue
  • Clip coord fix
  • [core,input] Add debug log to keyboa

Affected software

openSUSE-SU-2026:20339-1 is recorded against 1 package.

  • freerdp (fixed in 3.22.0-160000.1.1)

Timeline and source

Published on 10 March 2026 and last revised on 23 March 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-03-10
Updated 2026-08-20
Modified 2026-03-23
Fix URL N/A

Affected Packages

Software From version Fixed in
freerdp 3.22.0-160000.1.1

References

Similar Threats

Free Vulnerability Check

Is your site affected by openSUSE-SU-2026:20339-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against openSUSE-SU-2026:20339-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSESUSE 2026