Out-of-bounds Read Vulnerability in FreeRDP Remote Desktop Protocol Implementation
CVE-2026-31885
6.5MEDIUM
What is CVE-2026-31885?
FreeRDP, a popular open-source implementation of the Remote Desktop Protocol, contains a vulnerability that allows for an out-of-bounds read due to improper handling of predictor and step_index values in its MS-ADPCM and IMA-ADPCM decoders. This issue arises in versions prior to 3.24.0, potentially exposing users to security risks if unpatched. The vulnerability has been addressed in version 3.24.0, and users are encouraged to update their installations to mitigate potential exploitation.
Affected Version(s)
FreeRDP < 3.24.0
