Use of uninitialized resource in FreeRDP - #VU146577
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to use of uninitialized resource in the RDPGFX ResetGraphics serializer when handling ResetGraphics PDUs on an active RDPGFX dynamic virtual channel. A remote user can trigger a ResetGraphics operation to disclose sensitive information.
The issue can disclose between 20 and 300 bytes of stale heap memory, including heap pointers and GLib function pointers. Reaching the vulnerable path requires completion of the RDPGFX capability exchange.