{"id":"CVE-2026-91946","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-91946","summary":"FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fixed…","details":"FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fixed 340-byte wire format. Attackers can receive uninitialized heap memory including live pointers and GLib function addresses transmitted in the PDU, defeating heap ASLR and disclosing the GLib module base address.","published":"2026-09-15T16:17:47.990","modified":"2026-09-15T16:17:47.990","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/FreeRDP/FreeRDP/commit/483c9388119f06bac420d92053cff9ef94e83bea","label":"FreeRDP/FreeRDP@483c938"},"references":[{"type":"WEB","url":"https://github.com/FreeRDP/FreeRDP/commit/483c9388119f06bac420d92053cff9ef94e83bea"},{"type":"WEB","url":"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-r7jx-j9h7-j4xj"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/freerdp-before-3.31.0-information-disclosure-via-rdpgfx-resetgraphics"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-15T16:17:47.990"}}