Ubuntu FreeRDP Updates Address Multiple Security Issues

P2 — VALIDATE AND UPDATENot provided by the authority · Not provided by the authorityEXPLOITATION: NOT STATED

Quick Answer

Ubuntu published USN-8880-1 for FreeRDP on Ubuntu 26.04 (resolute) LTS, Ubuntu 24.04 (noble) LTS. Ubuntu does not state a CVSS base score in these notices. Install the fixed source-package versions for the exact release.

Match USN-8880-1 To Ubuntu Releases And Update

What to do now: Inventory affected Ubuntu releases, compare installed source-package versions with the notices, install the supported updates, validate dependent workloads, and retain evidence.

Open the authoritative advisory

Last verified: 2026-10-06 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.

Scope And Authority

Product scopeFreeRDP on Ubuntu 26.04 (resolute) LTS, Ubuntu 24.04 (noble) LTS
AdvisoryUSN-8880-1
CVEs
Authoritative release date2026-10-06 11:57:03.269461 UTC
Authority revision date2026-10-06 11:57:03.269461 UTC
Affected versionsThe Ubuntu releases and source packages enumerated in USN-8880-1: Ubuntu 26.04 (resolute) LTS, Ubuntu 24.04 (noble) LTS.
Fixed versionnoble: freerdp3 3.32.1+dfsg-0ubuntu0.24.04.1 / resolute: freerdp3 3.32.1+dfsg-0ubuntu0.26.04.1
CVSS base scoreNot provided by the authority
CVSS severityNot provided by the authority
Exploitation statusNot stated by the authority; no exploitation claim is inferred.

What Changed

Several security issues were fixed in FreeRDP. This update uses a new upstream release, which includes additional bug fixes. In general, a standard system update will make all the necessary changes.

What To Validate Now

  1. Inventory. Locate systems on Ubuntu 26.04 (resolute) LTS, Ubuntu 24.04 (noble) LTS; record the installed source package, repository pocket, ESM entitlement where applicable, owner, exposure, and dependencies.
  2. Establish applicability. Match the Ubuntu codename and source package to USN-8880-1. Do not infer applicability from a binary package name, a generic kernel label, or the number of CVEs alone.
  3. Remediate. Install the fixed source-package versions listed by Ubuntu through the supported security or ESM channel.
  4. Validate. Confirm the installed source-package version, test representative FreeRDP functions and recovery paths, and document exceptions.
  5. Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.

Operational Cautions

This is a new upstream release with additional bug fixes. Test authentication, gateways, certificates, graphics, clipboard, device redirection, and dependent applications. Preserve package-manager output, before-and-after versions, validation results, and rollback evidence.

Evidence To Retain

  • Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
  • UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
  • Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.

Related TechGeeks Resources

Authoritative References

Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.