OESA-2026-3643
Dashboard / Vulnerabilities / OESA-2026-3643
Summary: freerdp security update
Details: FreeRDP is a client implementation of the Remote Desktop Protocol (RDP) that follows Microsoft&apos;s open specifications. This package provides the client applications xfreerdp and wlfreerdp. Security Fix(es): FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability. The TLS hostname matcher (tls_match_hostname() in libfreerdp/crypto/tls.c) treats a wildcard pattern such as *.example.com as matching any hostname ending in .example.com, so it incorrectly accepts a wildcard certificate for multi-label subdomains like a.b.example.com (which OpenSSL's X509_check_host() rejects). This weakens TLS server authentication under wildcard-certificate conditions.(CVE-2026-67293)
References: https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3643, https://nvd.nist.gov/vuln/detail/CVE-2026-67293
Affected packages
Package
Name: freerdp
Purl: pkg:rpm/openEuler/freerdp&distro=openEuler-24.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
