FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uninitialized heap memory in Save Session Info PDU reserved padding fields. (CVE-2026-85089)
FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uninitialized heap memory in Save Session Info PDU reserved padding fields. Three PDU writers in libfreerdp/core/info.c (rdp_write_logon_info_v2, rdp_write_logon_info_plain, and rdp_write_logon_info_ex) use Stream_Seek instead of Stream_Zero for reserved pad bytes (up to 576 bytes), leaving previously freed heap contents in the outgoing PDU. Because the send buffer is allocated with malloc (not zeroed), stale heap data — which may include cleartext credentials from prior sessions — can be sent to the receiving peer. FreeRDP-based servers using rdpUpdate::SaveSessionInfo and freerdp-proxy (which forwards these PDUs) are affected, allowing disclosure of server/proxy process memory to a downstream client.
AI Analysis
Technical Summary
FreeRDP versions 3.0.0 through 3.30.0 transmit uninitialized heap memory in the Save Session Info PDU reserved padding fields due to improper handling of reserved pad bytes in three PDU writers (rdp_write_logon_info_v2, rdp_write_logon_info_plain, and rdp_write_logon_info_ex) within libfreerdp/core/info.c. These functions use Stream_Seek instead of Stream_Zero, leaving up to 576 bytes of previously freed heap data in the outgoing PDU. Since the send buffer is allocated with malloc and not zeroed, stale heap contents, which may include cleartext credentials from prior sessions, can be leaked to the receiving peer. This affects FreeRDP-based servers using rdpUpdate::SaveSessionInfo and freerdp-proxy forwarding these PDUs, allowing disclosure of server or proxy process memory to downstream clients. The vulnerability is tracked as CVE-2026-85089 and has a CVSS 3.1 base score of 6.5 (medium severity). A patch is available in FreeRDP version 3.31.0.
Potential Impact
The vulnerability allows disclosure of uninitialized heap memory from the server or proxy process to downstream clients. This memory may contain sensitive information such as cleartext credentials from prior sessions, potentially compromising confidentiality. There is no indication of integrity or availability impact. No known exploits in the wild have been reported.
Mitigation Recommendations
A patch is available in FreeRDP version 3.31.0 that corrects the handling of reserved padding bytes by zeroing them instead of leaving uninitialized memory. Users and administrators should upgrade affected FreeRDP versions to 3.31.0 or later to remediate this vulnerability.
FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uninitialized heap memory in Save Session Info PDU reserved padding fields. (CVE-2026-85089)
Description
FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uninitialized heap memory in Save Session Info PDU reserved padding fields. Three PDU writers in libfreerdp/core/info.c (rdp_write_logon_info_v2, rdp_write_logon_info_plain, and rdp_write_logon_info_ex) use Stream_Seek instead of Stream_Zero for reserved pad bytes (up to 576 bytes), leaving previously freed heap contents in the outgoing PDU. Because the send buffer is allocated with malloc (not zeroed), stale heap data — which may include cleartext credentials from prior sessions — can be sent to the receiving peer. FreeRDP-based servers using rdpUpdate::SaveSessionInfo and freerdp-proxy (which forwards these PDUs) are affected, allowing disclosure of server/proxy process memory to a downstream client.
CVSS v3.1
Score 6.5medium
Affected software
pkg:deb/ubuntu/freerdp?arch=source&distro=xenialpkg:deb/ubuntu/freerdp2?arch=source&distro=esm-infra/bionicpkg:deb/ubuntu/freerdp?arch=source&distro=bionicpkg:deb/ubuntu/freerdp2?arch=source&distro=esm-infra/focalpkg:deb/ubuntu/freerdp2?arch=source&distro=jammypkg:deb/ubuntu/freerdp3?arch=source&distro=noblepkg:deb/ubuntu/freerdp2?arch=source&distro=esm-apps/noblepkg:deb/ubuntu/freerdp3?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
FreeRDP versions 3.0.0 through 3.30.0 transmit uninitialized heap memory in the Save Session Info PDU reserved padding fields due to improper handling of reserved pad bytes in three PDU writers (rdp_write_logon_info_v2, rdp_write_logon_info_plain, and rdp_write_logon_info_ex) within libfreerdp/core/info.c. These functions use Stream_Seek instead of Stream_Zero, leaving up to 576 bytes of previously freed heap data in the outgoing PDU. Since the send buffer is allocated with malloc and not zeroed, stale heap contents, which may include cleartext credentials from prior sessions, can be leaked to the receiving peer. This affects FreeRDP-based servers using rdpUpdate::SaveSessionInfo and freerdp-proxy forwarding these PDUs, allowing disclosure of server or proxy process memory to downstream clients. The vulnerability is tracked as CVE-2026-85089 and has a CVSS 3.1 base score of 6.5 (medium severity). A patch is available in FreeRDP version 3.31.0.
Potential Impact
The vulnerability allows disclosure of uninitialized heap memory from the server or proxy process to downstream clients. This memory may contain sensitive information such as cleartext credentials from prior sessions, potentially compromising confidentiality. There is no indication of integrity or availability impact. No known exploits in the wild have been reported.
Mitigation Recommendations
A patch is available in FreeRDP version 3.31.0 that corrects the handling of reserved padding bytes by zeroing them instead of leaving uninitialized memory. Users and administrators should upgrade affected FreeRDP versions to 3.31.0 or later to remediate this vulnerability.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-85089
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:Pro:24.04:LTS","Ubuntu:26.04:LTS"]
- Cvss Version
- 3.1
Threat ID: 6aa47ebf55bf5e2cf58579e6
Added to database: 09/11/2026, 22:20:47 UTC
Last enriched: 09/11/2026, 22:48:01 UTC
Last updated: 09/12/2026, 00:47:07 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.