CVE-2026-91946 PUBLISHED

FreeRDP before 3.31.0 Information Disclosure via RDPGFX ResetGraphics

Assigner: VulnCheck
Reserved: 15.09.2026 Published: 15.09.2026 Updated: 15.09.2026

FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fixed 340-byte wire format. Attackers can receive uninitialized heap memory including live pointers and GLib function addresses transmitted in the PDU, defeating heap ASLR and disclosing the GLib module base address.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor FreeRDP
Product FreeRDP
Versions Default: unaffected
  • affected from 2.0.0 to 3.31.0 (excl.)
  • Version 3.31.0 is unaffected

Credits

  • sam4k reporter

References

Problem Types

  • Use of Uninitialized Resource CWE