Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-91946

Опубликовано: 15 сент. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fixed 340-byte wire format. Attackers can receive uninitialized heap memory including live pointers and GLib function addresses transmitted in the PDU, defeating heap ASLR and disclosing the GLib module base address.

A flaw was found in FreeRDP. This information disclosure vulnerability exists in the RDPGFX server's ResetGraphics Protocol Data Unit (PDU) serializer. It fails to properly initialize padding bytes, allowing a remote attacker to receive uninitialized heap memory. This can lead to the disclosure of sensitive data, including live pointers and GLib function addresses, which could defeat Address Space Layout Randomization (ASLR) and reveal the GLib module's base address.

Меры по смягчению последствий

To mitigate this issue, restrict network access to FreeRDP server instances to only trusted clients and networks. Configure firewall rules to limit inbound connections to the RDP port (typically 3389) from untrusted sources. If FreeRDP server functionality is not required, consider disabling or uninstalling the FreeRDP server component.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freerdpAffected
Red Hat Enterprise Linux 6freerdpNot affected
Red Hat Enterprise Linux 7freerdpAffected
Red Hat Enterprise Linux 8freerdpAffected
Red Hat Enterprise Linux 9freerdpAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-824
https://bugzilla.redhat.com/show_bug.cgi?id=2533913FreeRDP: FreeRDP: Information Disclosure via RDPGFX ResetGraphics PDU

EPSS

Процентиль: 37%
0.00427
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
4 дня назад

[GHSA-r7jx-j9h7-j4xj: FreeRDP RDPGFX ResetGraphics discloses up to 300 bytes of uninitialized heap memory]

CVSS3: 6.5
nvd
4 дня назад

FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fixed 340-byte wire format. Attackers can receive uninitialized heap memory including live pointers and GLib function addresses transmitted in the PDU, defeating heap ASLR and disclosing the GLib module base address.

CVSS3: 6.5
debian
4 дня назад

FreeRDP versions before 3.31.0 contain an information disclosure vulne ...

CVSS3: 6.5
github
4 дня назад

FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fixed 340-byte wire format. Attackers can receive uninitialized heap memory including live pointers and GLib function addresses transmitted in the PDU, defeating heap ASLR and disclosing the GLib module base address.

EPSS

Процентиль: 37%
0.00427
Низкий

6.5 Medium

CVSS3