FreeRDP

•

severity

6.5

published

An RDP client that has negotiated an active RDPGFX dynamic virtual channel can remotely disclose up to 300 bytes of uninitialized server heap memory in a single FreeRDP ResetGraphics response. This information disclosure can reveal heap and module addresses and affects versions 2.0.0 through 3.30.0.

FreeRDP is embedded by remote-desktop projects including GNOME Remote Desktop and KDE's KRdp; downstream exposure and whether the required channel state occurs before or after desktop-user authentication depend on the integration.

For a single monitor, the serializer writes only 40 defined bytes before moving the stream position to byte 340. Because affected releases allocate the stream buffer with malloc(), the unwritten 300-byte region retains prior heap contents and is still compressed and sent. The demonstrated leak revealed a heap address and the addresses of g_uint_hash and g_uint_equal, allowing recovery of heap ASLR and the GLib module base. Other allocator histories could expose protocol fragments, credentials, or other process data.

Reachability requires an active RDPGFX dynamic virtual channel, a completed capability exchange, and a graphics reset such as display creation or a monitor-layout change. The issue is classified as CWE-908 and CWE-200. FreeRDP 3.31.0 explicitly zeroes transmitted padding and is the first patched release.

CVE pending.

References

CVSS v3.1

6.5

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CVSS v3.1

6.5

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CVSS v3.1

6.5

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

SNtWaFrEtQ  lOoJoHk$iHn$gC  a5tU  y&o8u3rU  sVo$f1t8wZaLr0eL  cMr1i@tCiFc6aCl&lIy$.T

request briefing

request briefing

SRtQaJrYtI  lNoDoRkQiYnOgO  aWt#  yOo2uZr$  sDo9f&t6w7a&rYe1  c1rRi4t9iMcPaBlRlFyI.#

request briefing

request briefing

SRtYa8rHtC  lKoSo7kVi&nSg7  aItX  y&o4u%rC  sIoJfStKwTa2r4e@  cVr7i6t@iVcJa1lZl#y%.V

request briefing

request briefing

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026