FreeRDP is a client implementation of the Remote Desktop Protocol (RDP) that follows Microsoft's open specifications. This package provides the client applications xfreerdp and wlfreerdp.
Security Fix(es):
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability. The TLS hostname matcher (tls_match_hostname() in libfreerdp/crypto/tls.c) treats a wildcard pattern such as *.example.com as matching any hostname ending in .example.com, so it incorrectly accepts a wildcard certificate for multi-label subdomains like a.b.example.com (which OpenSSL's X509_check_host() rejects). This weakens TLS server authentication under wildcard-certificate conditions.(CVE-2026-67293)
{
"severity": "Critical"
}{
"aarch64": [
"freerdp-2.11.8-7.oe2403sp3.aarch64.rpm",
"freerdp-debuginfo-2.11.8-7.oe2403sp3.aarch64.rpm",
"freerdp-debugsource-2.11.8-7.oe2403sp3.aarch64.rpm",
"freerdp-devel-2.11.8-7.oe2403sp3.aarch64.rpm",
"freerdp-help-2.11.8-7.oe2403sp3.aarch64.rpm",
"libwinpr-2.11.8-7.oe2403sp3.aarch64.rpm",
"libwinpr-devel-2.11.8-7.oe2403sp3.aarch64.rpm"
],
"src": [
"freerdp-2.11.8-7.oe2403sp3.src.rpm"
],
"x86_64": [
"freerdp-2.11.8-7.oe2403sp3.x86_64.rpm",
"freerdp-debuginfo-2.11.8-7.oe2403sp3.x86_64.rpm",
"freerdp-debugsource-2.11.8-7.oe2403sp3.x86_64.rpm",
"freerdp-devel-2.11.8-7.oe2403sp3.x86_64.rpm",
"freerdp-help-2.11.8-7.oe2403sp3.x86_64.rpm",
"libwinpr-2.11.8-7.oe2403sp3.x86_64.rpm",
"libwinpr-devel-2.11.8-7.oe2403sp3.x86_64.rpm"
]
}