Bug 2533913 (CVE-2026-91946) - CVE-2026-91946 FreeRDP: FreeRDP: Information Disclosure via RDPGFX ResetGraphics PDU
Summary: CVE-2026-91946 FreeRDP: FreeRDP: Information Disclosure via RDPGFX ResetGraph...
Keywords:
Status: NEW
Alias: CVE-2026-91946
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2534063 2534064
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-15 15:48 UTC by OSIDB Bzimport
Modified: 2026-09-15 18:11 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-15 15:48:51 UTC
FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fixed 340-byte wire format. Attackers can receive uninitialized heap memory including live pointers and GLib function addresses transmitted in the PDU, defeating heap ASLR and disclosing the GLib module base address.


Note You need to log in before you can comment on or make changes to this bug.