CVE-2026-31885: FreeRDP has an out-of-bounds read in ADPCM decoders due to missing predictor/step_index bounds checks
Published Mar 13, 2026
·Updated
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, there is an out-of-bounds read in MS-ADPCM and IMA-ADPCM decoders due to unchecked predictor and stepindex values from input data. This vulnerability is fixed in 3.24.0.
Affected Software
2 affected components
FreeRDP freerdp<3.24.0
FreeRDP freerdp<3.24.0
Remediation
Event History
Mar 13, 2026
CVE Published
via MITRE·05:38 PM
Data Sourced
via MITRE·05:38 PM
DescriptionSeverityWeakness
Data Sourced
via Red Hat·06:04 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·07:54 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-31885?
The severity of CVE-2026-31885 is considered to be significant due to the potential for exploitation via out-of-bounds reads.
2
How do I fix CVE-2026-31885?
To mitigate CVE-2026-31885, upgrade FreeRDP to version 3.24.0 or later.
3
What versions of FreeRDP are affected by CVE-2026-31885?
FreeRDP versions prior to 3.24.0 are affected by CVE-2026-31885.
4
What kind of vulnerability is CVE-2026-31885?
CVE-2026-31885 is an out-of-bounds read vulnerability specifically found in ADPCM decoders.
5
Is there any known exploit for CVE-2026-31885?
As of now, there are no publicly available exploits specifically targeting CVE-2026-31885.