FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, there is an out-of-bounds read in MS-ADPCM and IMA-ADPCM decoders due to unchecked predictor and step_index values from input data. This vulnerability is fixed in 3.24.0.
References
| Link | Resource |
|---|---|
| https://github.com/FreeRDP/FreeRDP/commit/16df2300e1e3f5a51f68fb1626429e58b531b7c8 | Patch |
| https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-h23r-3988-3wf3 | Exploit Patch Vendor Advisory |
| https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-h23r-3988-3wf3 | Exploit Patch Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-03-13 19:54
Updated : 2026-03-17 12:58
NVD link : CVE-2026-31885
Mitre link : CVE-2026-31885
CVE.ORG link : CVE-2026-31885
JSON object : View
Products Affected
freerdp
- freerdp
CWE
CWE-125
Out-of-bounds Read
