Description
FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fixed 340-byte wire format. Attackers can receive uninitialized heap memory including live pointers and GLib function addresses transmitted in the PDU, defeating heap ASLR and disclosing the GLib module base address.
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch Now
AI Analysis

Impact

FreeRDP versions earlier than 3.31.0 contain a flaw in the RDPGFX server’s ResetGraphics PDU serializer where padding bytes in a fixed 340‑byte wire format are not initialized. This oversight allows an attacker to read uninitialized heap memory, exposing live pointers and GLib function addresses transmitted in the PDU, defeating heap ASLR by revealing the GLib module base address, effectively leaking sensitive runtime information.

Affected Systems

Any installation of FreeRDP using a version lower than 3.31.0 is vulnerable. The flaw applies to the RDPGFX component of the server deployments that accept RDP connections and run these earlier releases are affected.

Risk and Exploitability

The CVSS score of 7.1 indicates moderate severity with potential for significant impact if an attacker can send crafted RDP packets to the server. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KE exploits at the time of this assessment. Attackers would need the ability to communicate with the target’s RDP service, which is typically exposed; if they can do so, they could undermine ASLR and potentially leverage the leaked pointers for further exploitation, making it a tangible risk for systems exposing FreeRDP services.

Generated by OpenCVE AI on September 20, 2026 at 16:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade FreeRDP to version 3.31.0 or newer so the resetgraphics serializer properly initializes padding bytes
  • After upgrading, restart the FreeRDP service to ensure the new binary is in use
  • Block remote RDP access until the vulnerability is patched, or restrict RDP traffic to trusted IP ranges

Generated by OpenCVE AI on September 20, 2026 at 16:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-824
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fixed 340-byte wire format. Attackers can receive uninitialized heap memory including live pointers and GLib function addresses transmitted in the PDU, defeating heap ASLR and disclosing the GLib module base address.
Title FreeRDP before 3.31.0 Information Disclosure via RDPGFX ResetGraphics
First Time appeared Freerdp
Freerdp freerdp
Weaknesses CWE-908
CPEs cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*
Vendors & Products Freerdp
Freerdp freerdp
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T19:03:24.499Z

Reserved: 2026-09-15T11:07:01.913Z

Link: CVE-2026-91946

cve-icon Vulnrichment

Updated: 2026-09-21T19:02:07.357Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T16:17:47.990

Modified: 2026-09-24T12:14:07.923

Link: CVE-2026-91946

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-15T15:18:05Z

Links: CVE-2026-91946 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:30:18Z

Weaknesses
  • CWE-824

    Access of Uninitialized Pointer

  • CWE-908

    Use of Uninitialized Resource