stable

xrdp-0.10.6-1.fc43

FEDORA-2026-9417ff0bc5 created by bojan 3 months ago for Fedora 43

Security fixes

  • CVE-2026-32105
  • CVE-2026-32107
  • CVE-2026-32623
  • CVE-2026-32624
  • CVE-2026-33145
  • CVE-2026-33516
  • CVE-2026-33689
  • CVE-2026-35512

New features

  • Support for xorgxrdp bug fixes #249 and #342 (#3721)

Bug fixes

  • Honour pass_shell_as_env setting only if user sets a shell (#3725)
  • We no longer try to create a NULL authentication file when using VNC over UDS (#3727)
  • Problems with the Brazilian ABNT2 keyboard mapping have been corrected (#3728 3736)
  • A 'file exists' error when installing xrdp over an existing installation has been addressed (#3780)

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2026-9417ff0bc5

This update has been submitted for testing by bojan.

3 months ago

This update's test gating status has been changed to 'ignored'.

3 months ago

This update has been pushed to testing.

3 months ago
User Icon filiperosset commented & provided feedback 3 months ago
karma

no regressions noted

This update can be pushed to stable now if the maintainer wishes

3 months ago

bojan edited this update.

3 months ago

bojan edited this update.

3 months ago

This update has been submitted for stable by bodhi.

3 months ago

This update has been pushed to stable.

3 months ago

Please log in to add feedback.

Metadata
Type
security
Severity
high
Karma
1
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
7 days
Dates
submitted
3 months ago
in testing
3 months ago
in stable
3 months ago
modified
3 months ago
approved
3 months ago
BZ#2459298 CVE-2026-32105 xrdp: xrdp: Data integrity compromised due to missing MAC signature verification in Classic RDP Security [fedora-all]
0
0
BZ#2459302 CVE-2026-32107 xrdp: xrdp: Privilege Escalation via improper privilege management [fedora-all]
0
0
BZ#2459616 CVE-2026-33145 xrdp: xrdp: Arbitrary Command Execution via unsafe handling of AlternateShell parameter [fedora-all]
0
0
BZ#2459618 CVE-2026-32623 xrdp: xrdp NeutrinoRDP: Remote Code Execution or Denial of Service via heap-based buffer overflow in fragmented RDP data handling [fedora-all]
0
0
BZ#2459620 CVE-2026-35512 xrdp: xrdp: Remote Code Execution via heap-based buffer overflow [fedora-all]
0
0
BZ#2459621 CVE-2026-33516 xrdp: xrdp: Denial of Service and Information Disclosure via specially crafted RDP message [fedora-all]
0
0
BZ#2459623 CVE-2026-33689 xrdp: xrdp: Denial of Service and Information Disclosure via Out-of-Bounds Read [fedora-all]
0
0
BZ#2459625 CVE-2026-32624 xrdp: xrdp: Denial of Service via crafted username and domain name [fedora-all]
0
0

Automated Test Results