Public bug reported:

Regression in FreeRDP/WinPR 3.32.0 on Ubuntu 26.04.

Environment:

Ubuntu 26.04
gnome-remote-desktop 50.2-0ubuntu0.1

Broken versions:
libfreerdp3-3 3.32.0+dfsg-0ubuntu0.26.04.1
libfreerdp-server3-3 3.32.0+dfsg-0ubuntu0.26.04.1
libwinpr3-3 3.32.0+dfsg-0ubuntu0.26.04.1

Working versions:
libfreerdp3-3 3.31.0+dfsg-0ubuntu0.26.04.1
libfreerdp-server3-3 3.31.0+dfsg-0ubuntu0.26.04.1
libwinpr3-3 3.31.0+dfsg-0ubuntu0.26.04.1

Client:
Microsoft Windows App on macOS.

Symptom:

With FreeRDP/WinPR 3.32.0, Windows App stalls indefinitely at:

"Securing connection to remote PC..."

The same client/configuration worked before the upgrade.

Downgrading only the three FreeRDP/WinPR packages above from 3.32.0 to
3.31.0 immediately restores correct operation.

A Thincast RDP client works with both versions.

Below is a summary of the troubleshooting session with ChatGPT, may have
inaccuracies, but looks good to me (an RDP non-expert).

Protocol comparison with WLOG_LEVEL=debug:

Microsoft Windows App:

RDP_NEG_REQ:
RequestedProtocol: [SSL|HYBRID|HYBRID_EX][0x0000000b]

Negotiated Security:
NLA:0 EXT:1

Early User Auth active: true

CredSSP version 6 is negotiated and NTLM reaches:

NTLM_STATE_INITIAL
-> NTLM_STATE_NEGOTIATE
-> NTLM_STATE_CHALLENGE

It then stalls indefinitely. No NTLM_STATE_AUTHENTICATE is received.

The only server errors occur when the connection is manually cancelled:

[ERROR][com.freerdp.core.transport] - [transport_read_layer]: BIO_read retries 
exceeded
[ERROR][com.freerdp.core.peer] - [transport_read_layer]: 
ERRCONNECT_CONNECT_TRANSPORT_FAILED
[RDP] Network or intentional disconnect, stopping session

For comparison, Thincast negotiates:

RequestedProtocol: [SSL|HYBRID][0x00000003]
Negotiated Security: NLA:1 EXT:0
Early User Auth active: false

and successfully proceeds:

NTLM_STATE_NEGOTIATE
-> NTLM_STATE_CHALLENGE
-> NTLM_STATE_AUTHENTICATE
-> NTLM_STATE_FINAL

followed by public key authentication and auth info.

The .rdp file already contains:

enablerdsaadauth:i:0
enablecredsspsupport:i:1
use redirection server name:i:1

Therefore this appears to be a regression specifically in the server-
side PROTOCOL_HYBRID_EX / Early User Authorization path introduced or
exposed by FreeRDP 3.32.0.

Reproducer:

1. Run gnome-remote-desktop 50.2 with FreeRDP/WinPR 3.32.0.
2. Connect using Microsoft Windows App for macOS.
3. Observe that the client stalls at "Securing connection to remote PC..." 
after the server enters NTLM_STATE_CHALLENGE.
4. Downgrade libfreerdp3-3, libfreerdp-server3-3 and libwinpr3-3 to 3.31.0.
5. Restart gnome-remote-desktop.
6. The same Windows App connection succeeds.

Thincast works in both cases because it requests HYBRID rather than
HYBRID_EX.

ProblemType: Bug
DistroRelease: Ubuntu 26.04
Package: libfreerdp3-3 3.32.0+dfsg-0ubuntu0.26.04.1
ProcVersionSignature: Ubuntu 7.0.0-34.34~24.04.1-generic 7.0.14
Uname: Linux 7.0.0-34-generic x86_64
ApportVersion: 2.34.1-0ubuntu0.1
Architecture: amd64
CasperMD5CheckResult: unknown
CloudArchitecture: x86_64
CloudBuildName: server
CloudID: lxd
CloudName: lxd
CloudPlatform: lxd
CloudSerial: 20260918
CloudSubPlatform: LXD socket API v. 1.0 (/dev/lxd/sock)
Date: Tue Sep 29 18:38:37 2026
ProcEnviron:
 LANG=C.UTF-8
 PATH=(custom, no user)
 SHELL=/bin/bash
 TERM=xterm-256color
SourcePackage: freerdp3
UpgradeStatus: No upgrade log present (probably fresh install)

** Affects: freerdp3 (Ubuntu)
     Importance: Undecided
         Status: New


** Tags: amd64 apport-bug cloud-image resolute

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2168823

Title:
  FreeRDP 3.32.0 regression: gnome-remote-desktop stalls with Microsoft
  Windows App during HYBRID_EX/CredSSP authentication

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/freerdp3/+bug/2168823/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to