MEDIUM

CVE-2026-91946

2026-09-15 CVSS v3.1
CVSS
6.5

Description

FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fixed 340-byte wire format. Attackers can receive uninitialized heap memory including live pointers and GLib function addresses transmitted in the PDU, defeating heap ASLR and disclosing the GLib module base address.

Weakness (CWE)

CWE-908 Use of Uninitialized Resource

EPSS Score

0.43%
Probability of exploitation in next 30 days
36.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE