FreeRDP 3.27

Release published FreeRDP 3.27.0 is an open-source implementation of the Remote Desktop Protocol, including libraries and clients for connecting to RDP servers. The release was published on June 15, 2026, as stated in the official project note. The archives of the new version are uploaded to the FreeRDP release directory, and the complete set of changes is available through the comparison of 3.26.0…3.27.0 on GitHub.


The developers describe FreeRDP 3.27.0 as a major release with new features, bug fixes, and code cleanup. One of the main changes is stricter TLS parameters: the security level of TLS is now set to 2 by default, and the minimum supported version of TLS has been raised to TLS 1.2. This means that old and weak TLS configurations will no longer be used by default. If necessary, behavior can be overridden on the client side through the parameters /tls:seclevel: and /tls:enforce:, while server implementations can manage this through rdpSettings::FreeRDP_TLSMinVersion and rdpSettings::FreeRDP_TlsSecLevel, as specified in the FreeRDP 3.27.0 release notes.

Major changes in FreeRDP 3.27.0:

  • TLS is now stricter by default.
    In FreeRDP 3.27.0, the TLS security level is now set to 2 by default, and the minimum protocol version is TLS 1.2. This increases the baseline security of RDP connections and reduces the risk of using outdated cryptographic parameters. Explicit client settings /tls:seclevel: and /tls:enforce: have been retained for compatibility with older servers.

  • Improved support for Azure/Entra.
    The release includes extensions for more stable connections related to Azure/Entra. The developers clarify that this refers to known but officially undocumented extensions. In practice, this should enhance FreeRDP's performance in corporate scenarios where RDP access is tied to Microsoft Entra ID infrastructure.

  • Major update for the Android client.
    The Android client has received a significant set of changes again. The detailed list in the release note is not disclosed, but the developers separately thank participant @svncibrahim for their contribution. This continues the trend of previous releases, where the FreeRDP mobile client has been actively refined.

  • Changed handling of password hash on non-Windows systems.
    Password hash now uses a user-defined SSPI attribute on non-Windows systems. This is a low-level change in the authentication mechanism and integration with SSPI-compatible logic, primarily important for developers and builders using FreeRDP as a library.

  • Fixed the public RDP proxy API.
    Unstable structures have been removed from the public headers of the RDP proxy. The authors note that there are no known users of this internal API, but if someone has been relying on it directly, they should contact the developers. This change relates to API cleanup and reducing the risk of accidental dependence of external code on unstable internal structures.

  • Keyboard layout improved.
    The list of changes includes updates to keyboard mapping. Such changes are generally important for the correct transmission of local layouts and special keys in remote sessions, especially when connecting from Linux clients to Windows servers or non-standard RDP environments.

  • The RDPDR channel has been expanded.
    Channel RDPDR, responsible for device redirection, can now receive additional arguments. Developers emphasize that this does not break existing behavior but allows channels that support the new scheme to request additional parameters and use them accordingly.

  • Client statistics API added.
    FreeRDP now includes an API for logging client statistics. By default, it prints a trace log at the end of the session, but data can also be requested at any point during the connection. This is useful for diagnostics, monitoring the quality of RDP connections, and debugging clients built on top of libfreerdp.

  • Improved handling of deprecated WinPR symbols.
    This release fixes the handling of deprecated WinPR mechanisms and adds an option WITHOUT_WINPR_3x_DEPRECATED, allowing FreeRDP to be built without symbols marked as deprecated in the stable 3.x branch. This is important for maintainers of distributions and developers who want to prepare in advance for future API cleanup.

  • Vulnerabilities fixed.
    Along with FreeRDP 3.27.0, five GitHub Security Advisories have been published. Among them are a heap-buffer-overflow in TS Gateway RPC RESPONSE reassembly due to desynchronization of alloc_hint and the actual data size, fixed in 3.27.0 (GHSA-9gxm-3mf5-f5cx); heap-buffer-overflow in TS Gateway RPC fragment receive processing due to incorrect bind_ack max_xmit_frag limit (GHSA-7rp4-66mc-j9vx); out-of-bounds read in H.264 YUV-to-RGB conversion when decoder and surface sizes do not match (GHSA-3mmf-qh4f-frm6); heap-buffer-overflow write in AVC444 YUV buffer allocation (GHSA-vx73-w5q6-7jqr); as well as integer overflow in freerdp_image_copy_from_icon_data() (GHSA-5c5v-f78v-h2f6). Some of the issues affect clients connecting to a malicious RDP server or gateway, making the update particularly important for users connecting to external or untrusted RDP nodes.

  • New project participants.
    The release highlights new contributors: @ramnes, @grioghar, @scottgeigel2, @metsw24-max, and @zorjen122. For an infrastructure project like FreeRDP, this is crucial: it is used not only as an independent client but also as a library in other remote access solutions.

Overall, FreeRDP 3.27.0 appears not just as a cosmetic bug-fix release but as a practical update for administrators, client developers, and RDP users on Linux, BSD, macOS, Android, and other platforms. Major reasons to upgrade include tighter default TLS settings, compatibility improvements with Azure/Entra, updates to the Android client, and fixes for vulnerabilities affecting the client side of RDP connections.

Source: linux.org.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster