Amazon Linux 2023 Security Advisory: ALAS2023-2026-2142
Advisory Released Date: 2026-09-14
Advisory Updated Date: 2026-09-14
FAQs regarding Amazon Linux ALAS/CVE Severity
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, an authenticated RDP client can advertise DVI ADPCM with nBlockAlign equal to 8 and nChannels equal to 2 to make the `bs` calculation in rdpsnd_server_select_format in channels/rdpsnd/server/rdpsnd_main.c equal zero. The subsequent out_frames modulo `bs` operation raises SIGFPE and terminates the server-side rdpsnd channel process. This vulnerability fixed in 3.28.0. (CVE-2026-63117)
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, freerdp_dsp_decode_opus in libfreerdp/codec/dsp.c calls Stream_EnsureRemainingCapacity on context->common.buffer even though opus_decode writes decoded PCM into the caller-supplied out stream. A malicious RDP server that negotiates WAVE_FORMAT_OPUS with a client built with WITH_OPUS enabled and WITH_DSP_FFMPEG disabled can make libopus write a large decoded frame beyond the 4096-byte StreamPool_Take destination used by channels/rdpsnd/client/rdpsnd_main.c. This can corrupt the client heap, crash the client, and may permit code execution. This issue is fixed in version 3.28.0. (CVE-2026-63633)
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv_formats in channels/rdpsnd/server/rdpsnd_main.c frees context->client_formats on a malformed Client Audio Formats PDU without clearing the owning pointer or num_client_formats. An authenticated RDP client can trigger an error such as a cbSize larger than the remaining record, leave the dangling pointer in the server context, and cause rdpsnd_server_context_free to free the same allocation again at session teardown. This reliably terminates the server and can create allocator-dependent heap corruption. This issue is fixed in version 3.28.0. (CVE-2026-63652)
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.29.0, planar_decompress_plane_rle and planar_decompress_plane_rle_only in libfreerdp/codec/planar.c verify that a control byte exists but do not verify that the source buffer contains the zero to fifteen raw bytes declared by that control byte. A malicious RDP server can send a truncated planar bitmap or surface update whose final control byte claims additional raw bytes, causing the decoder to read beyond pSrcData while processing a color plane. This can crash the client and may disclose adjacent memory. This issue is fixed in version 3.29.0. (CVE-2026-69159)
A flaw was found in FreeRDP. This vulnerability allows a remote attacker with low privileges to disclose sensitive information from the server or proxy process memory to a downstream client. This occurs because certain functions responsible for writing Save Session Info Protocol Data Units (PDUs) use Stream_Seek instead of Stream_Zero for reserved padding fields, leading to the transmission of uninitialized heap memory that may contain cleartext credentials from previous sessions. (CVE-2026-85089)
A flaw was found in FreeRDP. A heap out-of-bounds read vulnerability exists in the `general_ChromaV1ToYUV444` function during AVC444 chroma plane reconstruction. A remote attacker, acting as a malicious Remote Desktop Protocol (RDP) server, can exploit this by sending a specially crafted `RFX_AVC444_BITMAP_STREAM` with specific frame geometry. This can lead to an out-of-bounds memory read, potentially disclosing sensitive heap data to the client or causing a client crash, resulting in a denial of service. (CVE-2026-85090)
Affected Packages:
freerdp
Issue Correction:
Run dnf update freerdp --releasever 2023.12.20260914 or dnf update --advisory ALAS2023-2026-2142 --releasever 2023.12.20260914 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation
aarch64:
freerdp-libs-debuginfo-3.31.0-1.amzn2023.aarch64
libwinpr-debuginfo-3.31.0-1.amzn2023.aarch64
freerdp-server-3.31.0-1.amzn2023.aarch64
freerdp-3.31.0-1.amzn2023.aarch64
freerdp-debugsource-3.31.0-1.amzn2023.aarch64
libwinpr-3.31.0-1.amzn2023.aarch64
freerdp-server-debuginfo-3.31.0-1.amzn2023.aarch64
libwinpr-devel-3.31.0-1.amzn2023.aarch64
freerdp-devel-3.31.0-1.amzn2023.aarch64
freerdp-debuginfo-3.31.0-1.amzn2023.aarch64
freerdp-libs-3.31.0-1.amzn2023.aarch64
src:
freerdp-3.31.0-1.amzn2023.src
x86_64:
freerdp-libs-debuginfo-3.31.0-1.amzn2023.x86_64
freerdp-server-3.31.0-1.amzn2023.x86_64
freerdp-server-debuginfo-3.31.0-1.amzn2023.x86_64
freerdp-debugsource-3.31.0-1.amzn2023.x86_64
freerdp-debuginfo-3.31.0-1.amzn2023.x86_64
libwinpr-debuginfo-3.31.0-1.amzn2023.x86_64
libwinpr-devel-3.31.0-1.amzn2023.x86_64
libwinpr-3.31.0-1.amzn2023.x86_64
freerdp-3.31.0-1.amzn2023.x86_64
freerdp-devel-3.31.0-1.amzn2023.x86_64
freerdp-libs-3.31.0-1.amzn2023.x86_64