Skip to finding
important · Zero-click

An unauthenticated RDP peer can execute code in GNOME Remote Desktop 51 pre-release Remote Login.

Affects

GNOME Remote Desktop 51 pre-release Remote Login deployments on Linux distributions embedding FreeRDP 3.28 through 3.30.

A rejected negotiation continues into a disabled security mechanism, after which a heap disclosure supplies addresses for a controlled eight-byte overwrite of a live function-pointer-bearing object.

Detail and 4 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Friday, September 4, 2026