{"affected":[{"ecosystem_specific":{"binaries":[{"libfreerdp2":"2.4.0-150400.3.41.1","libwinpr2":"2.4.0-150400.3.41.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP7","name":"freerdp","purl":"pkg:rpm/suse/freerdp&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.4.0-150400.3.41.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for freerdp fixes the following issues:\n\n- CVE-2026-22855: heap-buffer-overflow in smartcard_unpack_set_attrib_call (bsc#1256721).\n- CVE-2026-22857: heap-use-after-free in irp_thread_func (bsc#1256723).\n- CVE-2026-23533: improper validation can lead to heap buffer overflow in `clear_decompress_residual_data`\n  (bsc#1256943).\n- CVE-2026-23732: improper validation can lead to heap buffer overflow in `Glyph_Alloc` (bsc#1256945).\n- CVE-2026-23883: use-after-free when `update_pointer_color` and `freerdp_image_copy_from_pointer_data` fail\n  (bsc#1256946).\n- CVE-2026-23884: use-after-free in `gdi_set_bounds` (bsc#1256947).\n","id":"SUSE-SU-2026:0656-1","modified":"2026-02-26T15:06:36Z","published":"2026-02-26T15:06:36Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20260656-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256721"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256723"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256943"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256945"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256946"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256947"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-22855"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-22857"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23533"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23732"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23883"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23884"}],"related":["CVE-2026-22855","CVE-2026-22857","CVE-2026-23533","CVE-2026-23732","CVE-2026-23883","CVE-2026-23884"],"summary":"Security update for freerdp","upstream":["CVE-2026-22855","CVE-2026-22857","CVE-2026-23533","CVE-2026-23732","CVE-2026-23883","CVE-2026-23884"]}