GHSA-gw8v-xq42-vg69HighCVSS 6.5
FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX...
🔗 CVE IDs covered (1)
📋 Description
FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fixed 340-byte wire format. Attackers can receive uninitialized heap memory including live pointers and GLib function addresses transmitted in the PDU, defeating heap ASLR and disclosing the GLib module base address.
🔗 References (5)
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-r7jx-j9h7-j4xj
- https://nvd.nist.gov/vuln/detail/CVE-2026-91946
- https://github.com/FreeRDP/FreeRDP/commit/483c9388119f06bac420d92053cff9ef94e83bea
- https://www.vulncheck.com/advisories/freerdp-before-3.31.0-information-disclosure-via-rdpgfx-resetgraphics
- https://github.com/advisories/GHSA-gw8v-xq42-vg69