#VU125372 Reachable assertion in FreeRDP - CVE-2026-33977
Published: April 8, 2026
FreeRDP
FreeRDP
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to reachable assertion in freerdp_dsp_decode_ima_adpcm() and dsp_decode_ima_adpcm_sample() in libfreerdp/codec/dsp.c when processing RDPSND IMA ADPCM audio data from a server. A remote attacker can send a specially crafted audio block with an invalid initial step index to cause a denial of service.
Audio redirection must be enabled, which is the default configuration.