Bug 2533930 (CVE-2026-91963)
| Summary: | CVE-2026-91963 FreeRDP: FreeRDP: Remote code execution via uninitialized heap memory disclosure | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | rhel-process-autobot, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in FreeRDP. An uninitialized heap memory disclosure vulnerability exists in the urbdrc USB redirection channel. A malicious Remote Desktop Protocol (RDP) server can exploit this by inducing failing USB transfers, allowing it to read uninitialized heap memory from the client. This information disclosure can defeat Address Space Layout Randomization (ASLR), potentially enabling remote code execution when chained with other memory corruption vulnerabilities.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2534093, 2534096 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-09-15 15:51:34 UTC
|