From 5dd7f31d756f5ae3a7467645eb77a72e189d81b1 Mon Sep 17 00:00:00 2001 From: RHEL Packaging Agent Date: Wed, 24 Jun 2026 15:12:47 +0000 Subject: [PATCH] Fix incorrect bounds checks in planar codec (CVE-2026-45700) Backport upstream commit 4a065a941 to fix CVE-2026-45700 in freerdp 2.11.7. The patch corrects incorrect bounds checks in the planar codec's RLE decompression path where nDstStep was used instead of nTempStep, both in the bounds check condition and the corresponding error message in planar_decompress(). CVE: CVE-2026-45700 Upstream patches: - https://github.com/FreeRDP/FreeRDP/commit/4a065a941ae134a0433d1497c03b3c3eb91b9f85.patch Resolves: RHEL-186983 This commit was backported by Ymir, a Red Hat Enterprise Linux software maintenance AI agent. Assisted-by: Ymir --- codec-planar-fix-bounds-checks.patch | 31 ++++++++++++++++++++++++++++ freerdp.spec | 10 ++++++++- 2 files changed, 40 insertions(+), 1 deletion(-) create mode 100644 codec-planar-fix-bounds-checks.patch diff --git a/codec-planar-fix-bounds-checks.patch b/codec-planar-fix-bounds-checks.patch new file mode 100644 index 0000000..104a3ac --- /dev/null +++ b/codec-planar-fix-bounds-checks.patch @@ -0,0 +1,31 @@ +From 836d5b6f6d305ba6542fac8ba2d16b2e4e8b13a7 Mon Sep 17 00:00:00 2001 +From: Armin Novak +Date: Thu, 30 Apr 2026 15:03:21 +0200 +Subject: [PATCH] [codec,planar] fix bounds checks + +--- + libfreerdp/codec/planar.c | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/libfreerdp/codec/planar.c b/libfreerdp/codec/planar.c +index 9b4d13057..67fc4212e 100644 +--- a/libfreerdp/codec/planar.c ++++ b/libfreerdp/codec/planar.c +@@ -841,12 +841,12 @@ BOOL planar_decompress(BITMAP_PLANAR_CONTEXT* planar, const BYTE* pSrcData, UINT + return FALSE; + } + +- if ((nXDst + nSrcWidth) * bpp > nDstStep) ++ if ((nXDst + nSrcWidth) * bpp > nTempStep) + { + WLog_ERR(TAG, + "planar plane destination (X %" PRIu32 " + width %" PRIu32 + ") * bpp %" PRIu32 " exceeds stride %" PRIu32, +- nXDst, nSrcWidth, bpp, nDstStep); ++ nXDst, nSrcWidth, bpp, nTempStep); + return FALSE; + } + +-- +2.52.0 + diff --git a/freerdp.spec b/freerdp.spec index 8947a4f..f5b8a2c 100644 --- a/freerdp.spec +++ b/freerdp.spec @@ -27,7 +27,7 @@ Name: freerdp Version: 2.11.7 -Release: 9%{?dist} +Release: 10%{?dist} Epoch: 2 Summary: Free implementation of the Remote Desktop Protocol (RDP) License: ASL 2.0 @@ -191,6 +191,10 @@ Patch43: client-x11-improve-rails-window-locking.patch Patch44: client-x11-refactor-locking.patch Patch45: client-x11-fix-deadlock-on-output-expose.patch +# CVE-2026-45700 +# https://github.com/FreeRDP/FreeRDP/commit/4a065a941ae134a0433d1497c03b3c3eb91b9f85 +Patch46: codec-planar-fix-bounds-checks.patch + BuildRequires: gcc BuildRequires: gcc-c++ BuildRequires: alsa-lib-devel @@ -448,6 +452,10 @@ find %{buildroot} -name "*.a" -delete %{_libdir}/pkgconfig/winpr-tools2.pc %changelog +* Wed Jun 24 2026 RHEL Packaging Agent - 2:2.11.7-10 +- Fix incorrect bounds checks in planar codec (CVE-2026-45700) + Resolves: RHEL-186983 + * Tue May 05 2026 Ondrej Holy - 2:2.11.7-9 - Lock appWindow to fix use-after-free in RAIL mode (CVE-2026-25952) Resolves: RHEL-159850