Description
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, there is an out-of-bounds read in MS-ADPCM and IMA-ADPCM decoders due to unchecked predictor and step_index values from input data. This vulnerability is fixed in 3.24.0.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:HExploitability: 3.9 | Impact: 5.5Attack Vector: Network
Complexity: Low
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: Low
Availability: High
Affected Packages2 packages
🔴Vulnerability Details
2CVEListFreeRDP has an out-of-bounds read in ADPCM decoders due to missing predictor/step_index bounds checks↗2026-03-13 ▶ OSVCVE-2026-31885: FreeRDP is a free implementation of the Remote Desktop Protocol↗2026-03-13 ▶ 📋Vendor Advisories
2Red Hatfreerdp: FreeRDP has an out-of-bounds read in ADPCM decoders due to missing predictor/step_index bounds checks↗2026-03-13 ▶ DebianCVE-2026-31885: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0...↗2026 ▶ 🕵️Threat Intelligence
1WizCVE-2026-31885 Impact, Exploitability, and Mitigation Steps | Wiz↗ ▶