You have been subscribed to a public bug:

Summary
After the freerdp3 security update to 3.32.0+dfsg-0ubuntu0.26.04.1 
(USN-8836-1), remote desktop connections served by gnome-remote-desktop 
(headless system remote login, port 3389) hang before authentication. Every 
connection attempt stalls at the exact same protocol point and the server logs 
no NLA/CredSSP/redirection activity at all. Downgrading libfreerdp3-3, 
libfreerdp-server3-3 and libwinpr3-3 back to 3.31.0+dfsg-0ubuntu0.26.04.1 
immediately restores working remote login.

Environment
- Ubuntu 26.04.1 LTS, x86_64, headless server (ASPEED BMC, no GPU), kernel 
7.0.0-34-generic
- gnome-remote-desktop 50.2-0ubuntu0.1, system daemon with remote login enabled 
(grdctl --system rdp enable)
- RDP listening on *:3389, no firewall
- Client: macOS "Windows App" connecting over LAN

Symptoms
- Client connects, then sits on "Configuring remote PC" indefinitely; the GDM 
login screen is never shown.
- Server side the connection stays ESTABLISHED with no progress; `ss -tinp` 
repeatedly shows the same byte counters for a stalled connection: bytes_sent 
3996, bytes_received 2414 (deterministic across repeated attempts), no data for 
45+ seconds.
- journalctl -u gnome-remote-desktop contains no NLA / CredSSP / "[RDP] Sending 
server redirection" entries for these attempts.
- When the client gives up/disconnects, the server logs:
    [ERROR][com.freerdp.core.transport] - [transport_read_layer]: BIO_read 
retries exceeded
    ... ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
    [RDP] Network or intentional disconnect, stopping session

Compared with 3.31.0 (working)
With 3.31.0 the same client reaches the GDM login screen (system daemon logs 
"[RDP] Sending server redirection", the per-session handover daemon accepts the 
client) and login completes. Same machine, same client, same configuration.

Timeline / evidence (from /var/log/apt/history.log)
- 2026-09-29 06:38:57: unattended-upgrade upgraded libfreerdp3-3, 
libfreerdp-server3-3, libwinpr3-3 from 3.31.0+dfsg-0ubuntu0.26.04.1 to 
3.32.0+dfsg-0ubuntu0.26.04.1
- 2026-09-30 10:38: host rebooted (before the reboot the long-running 
gnome-remote-desktop daemon still had 3.31.0 loaded in memory and served 
connections correctly)
- First connection attempt after the reboot (~10:41) already stalls; every 
subsequent attempt stalls identically

Steps to reproduce
1. Install libfreerdp3-3 / libfreerdp-server3-3 / libwinpr3-3 
3.32.0+dfsg-0ubuntu0.26.04.1 and restart gnome-remote-desktop (or reboot).
2. Connect any RDP client to port 3389 (gnome-remote-desktop remote login mode).
3. Observe: connection hangs before authentication; server logs stay silent; 
deterministic stall at ~4 KB sent / ~2.4 KB received (see bytes above).

Workaround
Downgrade the three packages to 3.31.0+dfsg-0ubuntu0.26.04.1 (debs obtained 
from the ubuntu-security-proposed PPA archives) and restart 
gnome-remote-desktop; remote login works again immediately. The packages are 
currently held via apt-mark so the broken version is not reinstalled 
automatically.

References
- LP: #2168564 (freerdp3 3.32.0 security update)
- USN-8836-1
- FreeRDP 3.32.0 upstream release (2026-09-23) contains extensive 
security-negotiation changes (e.g. ExtSecurity and Early User Authorization 
Result PDU support plus related hardening), which is the main suspect area.

** Affects: ubuntu
     Importance: Undecided
         Status: New

-- 
[regression] RDP stalls before authentication with freerdp3 3.32.0 
(USN-8836-1); works after downgrade to 3.31.0
https://bugs.launchpad.net/bugs/2168930
You received this bug notification because you are a member of Ubuntu Bugs, 
which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to