CVE-2026-31883Disclosure(freerdp / freerdp)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch freerdp freerdp systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a size_t underflow in the IMA-ADPCM and MS-ADPCM audio decoders leads to heap-buffer-overflow write via the RDPSND audio channel. In libfreerdp/codec/dsp.c, the IMA-ADPCM and MS-ADPCM decoders subtract block header sizes from a size_t variable without checking for underflow. When nBlockAlign (received from the server) is set such that size % block_size == 0 triggers the header parsing at a point where size is smaller than the header (4 or 8 bytes), the subtraction wraps size to ~SIZE_MAX. The while (size > 0) loop then continues for an astronomical number of iterations. This vulnerability is fixed in 3.24.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-191

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freerdp

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-03-13); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
freerdp

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-03-13: 2Mentions · 2026-03-25: 2Mentions · 2026-04-01: 1Patch / Workaround · 2026-03-25: 1Patch / Workaround · 2026-04-01: 1Technical Details · 2026-03-13: 2Technical Details · 2026-03-25: 2Technical Details · 2026-04-01: 103-1303-2504-01
Signal classification2 categories
Disclosure
360.0%
Patch
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-132
Disclosure2
2026-03-252
Disclosure1Patch1
2026-04-011
Patch1
Full discourse5 posts
  • Wazuh@wazuh
    Patch

    FreeRDP is affected by CVE-2026-31883 (CVSS 9.8), a critical heap-buffer-overflow flaw in its audio decoders that may let a malicious RDP server corrupt memory via the RDPSND channel. Affects versions up to 3.23.2. Update to 3.24.0 or later. Read more: https://ow.ly/APFK50Yyz63 https://t.co/xKL21P6dKC

    Post summary

    CVE‑2026‑31883 is a critical heap‑buffer‑overflow in FreeRDP’s audio decoders that lets a malicious RDP server corrupt memory via the RDPSND channel; the issue is resolved by upgrading to version 3.24.0 or later.

    126052223.1K
    7.9K followersView on X
  • VulnTracker@vuln_tracker
    Disclosure

    @wazuh @wazuh Most people worry about attackers RDPing into their servers. CVE-2026-31883 flips that - a rogue RDP server exploits YOUR client through the audio channel. CVSS 9.8 heap overflow in FreeRDP affecting every version up to 3.23.2. https://vulntracker.io

    Post summary

    The tweet announces that CVE‑2026‑31883 is a heap‑overflow vulnerability in FreeRDP (up to 3.23.2) exploitable via the audio channel, with a high CVSS score of 9.8, as reported on vulntracker.io.

    00010101
    448 followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: SUSE pushes FreeRDP security update fixing 6 critical flaws including CVE-2026-31806 and CVE-2026-31883 that enable remote code execution across multiple Linux architectures. https://threatcluster.io/cluster/critical-vulnerabilities-in-freerdp-addressed-by-suse-securi-2dc5453b

    Post summary

    SUSE has released a security update for FreeRDP to remediate six critical vulnerabilities, including CVE‑2026‑31806 and CVE‑2026‑31883, which allow remote code execution on several Linux architectures. No active exploitation or PoC details are disclosed.

    0000039
    128 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-31883 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a size_t underflow in the IMA-ADPCM and MS-ADPCM audio decoders leads to heap-buffer… https://www.cve.org/CVERecord?id=CVE-2026-31883 ----- Traducción: CVE-2026-31883 Fre… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-31883, a size_t underflow in FreeRDP’s audio decoders that can cause a heap‑buffer overflow, but provides no PoC, patches, or evidence of active exploitation.

    0000035
    57 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-31883 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a size_t underflow in the IMA-ADPCM and MS-ADPCM audio decoders leads to heap-buffer… https://www.cve.org/CVERecord?id=CVE-2026-31883

    Post summary

    The text announces a heap-buffer overflow vulnerability in FreeRDP audio decoders caused by a size_t underflow, with no PoC, exploit code, or patch mentioned.

    00000226
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfreerdpfreerdp---

Explore more