Unrated severityNVD Advisory· Published Mar 13, 2026· Updated Mar 16, 2026
FreeRDP has a division-by-zero in ADPCM decoders when `nBlockAlign` is 0
CVE-2026-31884
Description
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, division by zero in MS-ADPCM and IMA-ADPCM decoders when nBlockAlign is 0, leading to a crash. In libfreerdp/codec/dsp.c, both ADPCM decoders use size % block_size where block_size = context->common.format.nBlockAlign. The nBlockAlign value comes from the Server Audio Formats PDU on the RDPSND channel. The value 0 is not validated anywhere before reaching the decoder. When nBlockAlign = 0, the modulo operation causes a SIGFPE (floating point exception) crash. This vulnerability is fixed in 3.24.0.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/FreeRDP/FreeRDP/commit/03b48b3601d867afccac1cdc6081de7a275edce7mitrex_refsource_MISC
- github.com/FreeRDP/FreeRDP/commit/16df2300e1e3f5a51f68fb1626429e58b531b7c8mitrex_refsource_MISC
- github.com/FreeRDP/FreeRDP/security/advisories/GHSA-jp7m-94ww-p56rmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.