Vulnerability Description
FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uninitialized heap memory in Save Session Info PDU reserved padding fields. Three PDU writers in libfreerdp/core/info.c (rdp_write_logon_info_v2, rdp_write_logon_info_plain, and rdp_write_logon_info_ex) use Stream_Seek instead of Stream_Zero for reserved pad bytes (up to 576 bytes), leaving previously freed heap contents in the outgoing PDU. Because the send buffer is allocated with malloc (not zeroed), stale heap data — which may include cleartext credentials from prior sessions — can be sent to the receiving peer. FreeRDP-based servers using rdpUpdate::SaveSessionInfo and freerdp-proxy (which forwards these PDUs) are affected, allowing disclosure of server/proxy process memory to a downstream client.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Freerdp | Freerdp | >= 3.0.0, < 3.31.0 |
Related Weaknesses (CWE)
References
- https://github.com/FreeRDP/FreeRDPProduct
- https://github.com/FreeRDP/FreeRDP/blob/3.30.0/libfreerdp/core/info.c#L1541Product
- https://github.com/FreeRDP/FreeRDP/commit/056cede398d71c1f2540baebc26ec3327a2493Patch
- https://github.com/FreeRDP/FreeRDP/commit/483c9388119f06bac420d92053cff9ef94e83bPatch
- https://github.com/FreeRDP/FreeRDP/releases/tag/3.31.0ProductRelease Notes
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-v649-94v2-p72qExploitMitigationVendor Advisory
- https://www.vulncheck.com/advisories/freerdp-before-3.31.0-information-disclosurPatchRelease NotesThird Party Advisory
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-v649-94v2-p72qExploitMitigationVendor Advisory
FAQ
What is CVE-2026-85089?
CVE-2026-85089 is a vulnerability with a CVSS score of 6.5 (MEDIUM). FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uninitialized heap memory in Save Session Info PDU reserved padding fields. Three PDU writers in libfreerdp/core/info.c (rdp_write_logon_...
How severe is CVE-2026-85089?
CVE-2026-85089 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-85089?
Check the references section above for vendor advisories and patch information. Affected products include: Freerdp Freerdp.