#VU125358 Heap-based buffer overflow in FreeRDP - CVE-2026-31883
Published: April 8, 2026
FreeRDP
FreeRDP
Description
The vulnerability allows a remote attacker to overwrite heap memory.
The vulnerability exists due to a heap-based buffer overflow in the IMA-ADPCM and MS-ADPCM audio decoders in libfreerdp/codec/dsp.c when processing crafted RDPSND audio format and wave data. A remote attacker can send specially crafted RDPSND audio data to overwrite heap memory.
Audio data is processed automatically during an RDP session when RDPSND is negotiated.