Amazon Linux 2 : freerdp, --advisory ALAS2-2026-3840 (ALAS-2026-3840)

medium Nessus Plugin ID 332057

Synopsis

The remote Amazon Linux 2 host is missing a security update.

Description

The version of freerdp installed on the remote host is prior to 2.11.7-1. It is, therefore, affected by multiple vulnerabilities as referenced in the ALAS2-2026-3840 advisory.

Heap-buffer-overflow write in TS Gateway RPC fragment receive due to uncapped bind_ack max_xmit_frag

On TS Gateway connections, rpc->max_recv_frag is initialized to 0x0FF8 (4088) and ReceiveFragment is allocated to that size. In rpc_bind.c, the client assigns rpc->max_recv_frag = header.bind_ack.max_xmit_frag from the server without an upper bound. A malicious gateway can set max_xmit_frag = 0xFFFF while ReceiveFragment is never resized.

Later, rpc_client.c rejects fragments with if (header.frag_length > rpc->max_recv_frag). When both values are 65535, the check passes (65535 > 65535 is false). The receive loop then calls rpc_channel_read() - BIO_read() into the fixed 4088-byte ReceiveFragment, writing up to 65535 bytes and overflowing by up to 61447 attacker-controlled bytes. (CVE-2026-55193)

Heap-buffer-overflow write in TS Gateway RPC RESPONSE reassembly due to alloc_hint capacity mismatch

In rpc_client_recv_fragment(), when reassembling a PTYPE_RESPONSE PDU, the client calls Stream_EnsureCapacity(pdu->s, response->alloc_hint) using only the server-declared alloc_hint.
Stream_EnsureCapacity() returns success if the existing capacity is already >= alloc_hint, without considering the current write offset or the actual stub length about to be copied.

A malicious gateway can set a small alloc_hint (e.g. 100) while sending a large fragment (frag_length = 6000, yielding StubLength [?] 5968). The 4096-byte reassembly buffer is not grown, and Stream_Write(pdu->s, ..., StubLength) copies attacker-controlled stub data past the end of the heap allocation. On default builds this may abort via WINPR_ASSERT; on Release builds (NDEBUG) the assert is elided and the overflow becomes an exploitable heap write.

This is distinct from the separate ReceiveFragment / bind_ack max_xmit_frag issue (different buffer and code path in the same gateway module). (CVE-2026-55194)

Out-of-bounds read in glyph_cache_get via crafted glyph fragments

A malicious RDP server can trigger an out-of-bounds heap read in a FreeRDP client through the glyph cache.
glyph_cache_get() bounds-checks the index with > where it should use >= -- the sibling glyph_cache_put() already gets it right. Since the cache's entries array holds exactly number pointers, an index equal to number slips past the check and reads one slot past the end, which the caller then dereferences as a glyph. It's the read-side twin of CVE-2020-11098 (the write side was fixed back in 2.1.2; the read side never was), and it's still present in 3.25.0 and master. (CVE-2026-55564)

Integer Overflow in freerdp_image_copy_from_icon_data Bypasses Bounds Check (CVE-2026-55648)

Out-of-bounds read in the camera device enumerator server (rdpecam) via unterminated DeviceName / VirtualChannelName (CVE-2026-57157)

planar_decompress_plane_rle_only: heap OOB read -- incomplete fix for CVE-2026-23530

The fix for CVE-2026-23530 (GHSA-r4hv-852m-fq7p) correctly adds dimension guardsat the entry point of freerdp_bitmap_decompress_planar but is incomplete in scope.planar_decompress_plane_rle_only dereferences
*srcp before validating thatsrcp is within SrcSize. A malicious server can reach this path via a truncatedRLE planar payload in RDPGFX_CMDID_WIRETOSURFACE_1. (CVE-2026-57158)

Tenable has extracted the preceding description block directly from the tested product security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Run 'yum update freerdp' or or 'yum update --advisory ALAS2-2026-3840' to update your system.

See Also

https://alas.aws.amazon.com//AL2/ALAS2-2026-3840.html

https://alas.aws.amazon.com/faqs.html

https://explore.alas.aws.amazon.com/CVE-2026-55193.html

https://explore.alas.aws.amazon.com/CVE-2026-55194.html

https://explore.alas.aws.amazon.com/CVE-2026-55564.html

https://explore.alas.aws.amazon.com/CVE-2026-55648.html

https://explore.alas.aws.amazon.com/CVE-2026-57157.html

https://explore.alas.aws.amazon.com/CVE-2026-57158.html

Plugin Details

Severity: Medium

ID: 332057

File Name: al2_ALAS-2026-3840.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 8/4/2026

Updated: 8/4/2026

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.09

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:C

CVSS Score Source: CVE-2026-57158

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 8.2

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 5.1

Threat Score: 2

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N

Vulnerability Information

CPE: cpe:/o:amazon:linux:2, p-cpe:/a:amazon:linux:freerdp-debuginfo, p-cpe:/a:amazon:linux:freerdp-devel, p-cpe:/a:amazon:linux:freerdp-libs, p-cpe:/a:amazon:linux:freerdp, p-cpe:/a:amazon:linux:libwinpr-devel, p-cpe:/a:amazon:linux:libwinpr

Required KB Items: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/4/2026

Vulnerability Publication Date: 6/18/2026

Reference Information

CVE: CVE-2026-55193, CVE-2026-55194, CVE-2026-55564, CVE-2026-55648, CVE-2026-57157, CVE-2026-57158