Use of uninitialized resource in FreeRDP - #VU146577

 

Use of uninitialized resource in FreeRDP - #VU146577

Published: September 1, 2026


Vulnerability identifier: #VU146577
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-908
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to use of uninitialized resource in the RDPGFX ResetGraphics serializer when handling ResetGraphics PDUs on an active RDPGFX dynamic virtual channel. A remote user can trigger a ResetGraphics operation to disclose sensitive information.

The issue can disclose between 20 and 300 bytes of stale heap memory, including heap pointers and GLib function pointers. Reaching the vulnerable path requires completion of the RDPGFX capability exchange.


Affected software

FreeRDP

Remediation

Install security update from vendor's website.

FreeRDP - update to 3.31.0

External References

Related Security Bulletins