stable

xorgxrdp-0.10.5-1.fc42 and xrdp-0.10.5-1.fc42

FEDORA-2026-b409dad73e created by bojan 8 months ago for Fedora 42

Release notes for xrdp v0.10.5 (2026/01/27)

Security fixes

  • CVE-2025-68670: Improper bounds checking of domain string length leads to Stack-based Buffer Overflow

New features

  • It is now possible to start the xrdp daemon entirely unprivileged from the service manager (#3599 #3603). If you do this certain restrictions will apply. See https://github.com/neutrinolabs/xrdp/wiki/Running-the-xrdp-process-as-non-root for details.
  • TLS pre-master secrets can now be recorded for packet captures (#3617)
  • Add a FuseRootReportMaxFree to work around 'no free space' issues with some file managers (#3639)
  • Alternate shell names can now be passed to startwm.sh in an environment variable for more system management control (#3624 #3651)
  • Updated Xorg paths in sesman.ini to include more recent distros (#3663)
  • Add Slovenian keyboard (#3668 #3670)
  • xrdpapi: Add a way to monitor connect/disconnect events (#3693)

Bug fixes

  • Allow an empty X11 UTF8_STRING to be pasted to the clipboard (#3580 #3582)
  • Fix a regression introduced in v0.10.x, where it became impossible to connect to a VNC server which did not support the ExtendedDesktopSize encoding (#3540 #3584)
  • Fix a regression introduced in v0.10.x related to PAM groups handling (#3594)
  • Inconsistencies with [MS-RDPBCGR] have been addressed (#3608)
  • A reference to uninitialised data within the verify_user_pam_userpass.c module has been fixed (#3638)
  • Prevent some possible crashes when the RFX encoder is resized (#3590 #3644)
  • Fixes a regression introduced by GFX development which prevented the JPEG encoder from working correctly (#3649)
  • Fixes a regression introduced by #2974 which resulted in the xrdp PID file being deleted unexpectedly (#3650)
  • Do not overwrite a VNC port set by the user when not using sesman (#3674)
  • Fix regression from 0.9.x when freerdp client uses /workarea (#3618 #3676)
  • Fixes a crash where a resize is attempted with drdynvc disabled (#3672 #3680)
  • getgrouplist() now compiles on MacOS (#3575)
  • Various Coverity warnings have been addressed (#3656)
  • Documentation improvements (#3665)

Internal changes

  • An unnecessary include of sys/signal.h causing a compile warning on MUSL-C has been removed (#3679)

Release notes for xorgxrdp v0.10.5 (2026/01/28)

Bug fixes

  • Fix bug in Chrome pointer detection (#394 #396)

Internal changes

  • CI: Update FreeBSD xrdp dependency (#398)

Logout Required
After installing this update it is required that you logout of your current user session and log back in to ensure the changes supplied by this update are applied properly.

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2026-b409dad73e

This update has been submitted for testing by bojan.

8 months ago

This update's test gating status has been changed to 'ignored'.

8 months ago

This update has been pushed to testing.

8 months ago

bojan edited this update.

New build(s):

  • xorgxrdp-0.10.5-1.fc42

Karma has been reset.

8 months ago

This update has been submitted for testing by bojan.

8 months ago

This update has been pushed to testing.

8 months ago

This update has been submitted for stable by bodhi.

7 months ago

This update has been pushed to stable.

7 months ago

Please log in to add feedback.

Metadata
Type
security
Severity
high
Karma
0
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
7 days
Dates
submitted
8 months ago
in testing
8 months ago
in stable
7 months ago
modified
8 months ago
approved
7 months ago
BZ#1908387 Windows with transparency show whatever is below
0
0
BZ#2279775 xrdp socketdir not cleaned up on package removal
0
0
BZ#2322105 AltGr on Spanish keyboards
0
0
BZ#2323097 Requesting clarification on the License of xrdp rpm.
0
0
BZ#2433438 CVE-2025-68670 xorgxrdp: xrdp: Remote code execution via unauthenticated stack-based buffer overflow [epel-8]
0
0
BZ#2433439 CVE-2025-68670 xrdp: xrdp: Remote code execution via unauthenticated stack-based buffer overflow [epel-8]
0
0
BZ#2433440 CVE-2025-68670 xorgxrdp: xrdp: Remote code execution via unauthenticated stack-based buffer overflow [epel-9]
0
0
BZ#2433441 CVE-2025-68670 xrdp: xrdp: Remote code execution via unauthenticated stack-based buffer overflow [epel-9]
0
0
BZ#2433442 CVE-2025-68670 xorgxrdp: xrdp: Remote code execution via unauthenticated stack-based buffer overflow [fedora-all]
0
0
BZ#2433840 xorgxrdp-0.10.5 is available
0
0

Automated Test Results