diff --git a/codec-planar-fix-bounds-checks.patch b/codec-planar-fix-bounds-checks.patch new file mode 100644 index 0000000..104a3ac --- /dev/null +++ b/codec-planar-fix-bounds-checks.patch @@ -0,0 +1,31 @@ +From 836d5b6f6d305ba6542fac8ba2d16b2e4e8b13a7 Mon Sep 17 00:00:00 2001 +From: Armin Novak +Date: Thu, 30 Apr 2026 15:03:21 +0200 +Subject: [PATCH] [codec,planar] fix bounds checks + +--- + libfreerdp/codec/planar.c | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/libfreerdp/codec/planar.c b/libfreerdp/codec/planar.c +index 9b4d13057..67fc4212e 100644 +--- a/libfreerdp/codec/planar.c ++++ b/libfreerdp/codec/planar.c +@@ -841,12 +841,12 @@ BOOL planar_decompress(BITMAP_PLANAR_CONTEXT* planar, const BYTE* pSrcData, UINT + return FALSE; + } + +- if ((nXDst + nSrcWidth) * bpp > nDstStep) ++ if ((nXDst + nSrcWidth) * bpp > nTempStep) + { + WLog_ERR(TAG, + "planar plane destination (X %" PRIu32 " + width %" PRIu32 + ") * bpp %" PRIu32 " exceeds stride %" PRIu32, +- nXDst, nSrcWidth, bpp, nDstStep); ++ nXDst, nSrcWidth, bpp, nTempStep); + return FALSE; + } + +-- +2.52.0 + diff --git a/freerdp.spec b/freerdp.spec index 8947a4f..f5b8a2c 100644 --- a/freerdp.spec +++ b/freerdp.spec @@ -27,7 +27,7 @@ Name: freerdp Version: 2.11.7 -Release: 9%{?dist} +Release: 10%{?dist} Epoch: 2 Summary: Free implementation of the Remote Desktop Protocol (RDP) License: ASL 2.0 @@ -191,6 +191,10 @@ Patch43: client-x11-improve-rails-window-locking.patch Patch44: client-x11-refactor-locking.patch Patch45: client-x11-fix-deadlock-on-output-expose.patch +# CVE-2026-45700 +# https://github.com/FreeRDP/FreeRDP/commit/4a065a941ae134a0433d1497c03b3c3eb91b9f85 +Patch46: codec-planar-fix-bounds-checks.patch + BuildRequires: gcc BuildRequires: gcc-c++ BuildRequires: alsa-lib-devel @@ -448,6 +452,10 @@ find %{buildroot} -name "*.a" -delete %{_libdir}/pkgconfig/winpr-tools2.pc %changelog +* Wed Jun 24 2026 RHEL Packaging Agent - 2:2.11.7-10 +- Fix incorrect bounds checks in planar codec (CVE-2026-45700) + Resolves: RHEL-186983 + * Tue May 05 2026 Ondrej Holy - 2:2.11.7-9 - Lock appWindow to fix use-after-free in RAIL mode (CVE-2026-25952) Resolves: RHEL-159850