SUSE SLED15: freerdp / freerdp-devel / freerdp-proxy / freerdp-proxy-plugins / etc (SUSE-SU-2026:3562-1)

high Nessus Plugin ID 334787

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLED15 / SLED_SAP15 / SLES15 / SLES_SAP15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:3562-1 advisory.

- CVE-2026-27951: 32-bit system denial of service via endless blocking loop in `Stream_EnsureCapacity` (bsc#1258939).
- CVE-2026-33952: client denial of service via unvalidated authentication length field (bsc#1261196).
- CVE-2026-33977: client denial of service via malformed IMA ADPCM audio data (bsc#1261198).
- CVE-2026-33982: heap buffer overread in `winpr_aligned_offset_recalloc()` can lead to undefined behavior (bsc#1261222).
- CVE-2026-33983: improper error handling can lead to use of incorrect shift exponent, undefined behavior and an 80 billion iteration loop (bsc#1261200).
- CVE-2026-33984: heap buffer overflow allows arbitrary code execution via crafted pixel data (bsc#1261211).
- CVE-2026-33985: heap out-of-bounds read can leak sensitive data when pixel data is rendered to screen (bsc#1261217).
- CVE-2026-33986: heap out-of-bounds write due to H.264 YUV buffer dimension desync (bsc#1261223).
- CVE-2026-33987: heap out-of-bounds write due to persistent cache `bmpSize` desync (bsc#1261226).
- CVE-2026-33995: double-free in `kerberos_AcceptSecurityContext()` and `kerberos_InitializeSecurityContextA()` can lead to crash during NLA connection teardown with a failed authentication attempt (bsc#1261227).
- CVE-2026-40033: heap buffer overflow in `gdi_CacheToSurface` allows attackers to cause a denial of service or achieve remote code execution (bsc#1266317).
- CVE-2026-40254: off-by-one error in `contains_dotdot()` allows for drive channel path traversal (bsc#1262743).
- CVE-2026-44420: heap buffer overwrite can be triggered in server-side clipboard channel when a malicious client sends a `CB_CLIP_CAPS` PDU with a too-small `capabilitySetLength` (bsc#1267008).
- CVE-2026-44421: improper validation in `gdi_CacheToSurface` can lead to a heap buffer overwrite client when an RDP server sends crafted RDPGFX PDUs (bsc#1267009).
- CVE-2026-44422: improper memory management can lead to heap use-after-free/double-free in a client's RDPEAR authentication-redirection path (bsc#1267010).
- CVE-2026-45700: data check bypass when decoding RLE planar data can lead to an out-of-bounds heap write (bsc#1267011).
- CVE-2026-56297: improper synchronization of `channel_callback` access can lead to use-after-free in `dvcman_channel_close` and `dvcman_call_on_receive` triggered by a malicious RDP server (bsc#1271071).
- CVE-2026-57156: integer overflow in `update_read_delta_points` allows malicious RDP peers to cause a heap buffer overflow (bsc#1271303).
- CVE-2026-57157: 2-byte heap out-of-bounds read via attacker-supplied MS-RDPECAM `DeviceName` and `VirtualChannelName` fields (bsc#1271304).
- CVE-2026-57158: incomplete fix for CVE-2026-23530 in `planar_decompress_plane_rle_only` allows a malicious RDP server to trigger a one byte buffer overflow via a truncated `RDPGFX_CMDID_WIRETOSURFACE_1` planar payload (bsc#1271305).

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1258939

https://bugzilla.suse.com/1261196

https://bugzilla.suse.com/1261198

https://bugzilla.suse.com/1261200

https://bugzilla.suse.com/1261211

https://bugzilla.suse.com/1261217

https://bugzilla.suse.com/1261222

https://bugzilla.suse.com/1261223

https://bugzilla.suse.com/1261226

https://bugzilla.suse.com/1261227

https://bugzilla.suse.com/1262743

https://bugzilla.suse.com/1266317

https://bugzilla.suse.com/1267008

https://bugzilla.suse.com/1267009

https://bugzilla.suse.com/1267010

https://bugzilla.suse.com/1267011

https://bugzilla.suse.com/1271071

https://bugzilla.suse.com/1271303

https://bugzilla.suse.com/1271304

https://bugzilla.suse.com/1271305

https://www.suse.com/security/cve/CVE-2026-27951

https://www.suse.com/security/cve/CVE-2026-33952

https://www.suse.com/security/cve/CVE-2026-33977

https://www.suse.com/security/cve/CVE-2026-33982

https://www.suse.com/security/cve/CVE-2026-33983

https://www.suse.com/security/cve/CVE-2026-33984

https://www.suse.com/security/cve/CVE-2026-33985

https://www.suse.com/security/cve/CVE-2026-33986

https://www.suse.com/security/cve/CVE-2026-33987

https://www.suse.com/security/cve/CVE-2026-33995

https://www.suse.com/security/cve/CVE-2026-40033

https://www.suse.com/security/cve/CVE-2026-40254

https://www.suse.com/security/cve/CVE-2026-44420

https://www.suse.com/security/cve/CVE-2026-44421

https://www.suse.com/security/cve/CVE-2026-44422

https://www.suse.com/security/cve/CVE-2026-45700

https://www.suse.com/security/cve/CVE-2026-56297

https://www.suse.com/security/cve/CVE-2026-57156

https://www.suse.com/security/cve/CVE-2026-57157

https://www.suse.com/security/cve/CVE-2026-57158

http://www.nessus.org/u?fe14e44e

Plugin Details

Severity: High

ID: 334787

File Name: suse_SU-2026-3562-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 8/12/2026

Updated: 8/12/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.84

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-57156

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.7

Threat Score: 7.4

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-40033

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:freerdp-devel, p-cpe:/a:novell:suse_linux:freerdp-proxy-plugins, p-cpe:/a:novell:suse_linux:freerdp-proxy, p-cpe:/a:novell:suse_linux:freerdp-sdl, p-cpe:/a:novell:suse_linux:freerdp-server, p-cpe:/a:novell:suse_linux:freerdp-wayland, p-cpe:/a:novell:suse_linux:freerdp, p-cpe:/a:novell:suse_linux:libfreerdp-server-proxy3-3, p-cpe:/a:novell:suse_linux:libfreerdp3-3, p-cpe:/a:novell:suse_linux:librdtk0-0, p-cpe:/a:novell:suse_linux:libuwac0-0, p-cpe:/a:novell:suse_linux:libwinpr3-3, p-cpe:/a:novell:suse_linux:winpr-devel

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/10/2026

Vulnerability Publication Date: 2/25/2026

Reference Information

CVE: CVE-2026-27951, CVE-2026-33952, CVE-2026-33977, CVE-2026-33982, CVE-2026-33983, CVE-2026-33984, CVE-2026-33985, CVE-2026-33986, CVE-2026-33987, CVE-2026-33995, CVE-2026-40033, CVE-2026-40254, CVE-2026-44420, CVE-2026-44421, CVE-2026-44422, CVE-2026-45700, CVE-2026-56297, CVE-2026-57156, CVE-2026-57157, CVE-2026-57158

IAVA: 2026-A-0257-S, 2026-A-0286-S, 2026-A-0602, 2026-A-0656

SuSE: SUSE-SU-2026:3562-1