FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fixed 340-byte wire format. Attackers can receive uninitialized heap memory including live pointers and GLib function addresses transmitted in the PDU, defeating heap ASLR and disclosing the GLib module base address.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-908"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/91xxx/CVE-2026-91946.json"
}"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-91946.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "231867432041682170192096907494199930447",
"length": 538
},
"id": "CVE-2026-91946-40e2ddd5",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/freerdp/freerdp/commit/483c9388119f06bac420d92053cff9ef94e83bea",
"target": {
"file": "winpr/libwinpr/utils/stream.c",
"function": "Stream_New"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"66526936321550674325845669864391672062",
"149106399525389394430996085745748489367",
"59677448220993466901669150830539309647",
"205118646075812973770254754242893582082"
],
"threshold": 0.9
},
"id": "CVE-2026-91946-af7be01d",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/freerdp/freerdp/commit/483c9388119f06bac420d92053cff9ef94e83bea",
"target": {
"file": "winpr/libwinpr/utils/stream.c"
}
}
]
"2026-10-06T08:31:44Z"