
CVE-2026-91946
FreeRDP
•
severity
published
An RDP client that has negotiated an active RDPGFX dynamic virtual channel can remotely disclose up to 300 bytes of uninitialized server heap memory in a single FreeRDP ResetGraphics response. This information disclosure can reveal heap and module addresses and affects versions 2.0.0 through 3.30.0.
FreeRDP is embedded by remote-desktop projects including GNOME Remote Desktop and KDE's KRdp; downstream exposure and whether the required channel state occurs before or after desktop-user authentication depend on the integration.
For a single monitor, the serializer writes only 40 defined bytes before moving the stream position to byte 340. Because affected releases allocate the stream buffer with malloc(), the unwritten 300-byte region retains prior heap contents and is still compressed and sent. The demonstrated leak revealed a heap address and the addresses of g_uint_hash and g_uint_equal, allowing recovery of heap ASLR and the GLib module base. Other allocator histories could expose protocol fragments, credentials, or other process data.
Reachability requires an active RDPGFX dynamic virtual channel, a completed capability exchange, and a graphics reset such as display creation or a monitor-layout change. The issue is classified as CWE-908 and CWE-200. FreeRDP 3.31.0 explicitly zeroes transmitted padding and is the first patched release.
CVE pending.
References
Explore our other findings
