FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, a malicious RDP server can crash the FreeRDP client by sending audio data in IMA ADPCM format with an invalid initial step index value (>= 89). The unvalidated step index is read directly from the network and used to index into a 89-entry lookup table, triggering a WINPR_ASSERT() failure and process abort via SIGABRT. This affects any FreeRDP client that has audio redirection (RDPSND) enabled, which is the default configuration. This issue has been patched in version 3.24.2.
{
"cwe_ids": [
"CWE-617"
],
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33977.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"fixed": "3.24.2"
}
],
"source": "AFFECTED_FIELD"
}
]
}[
{
"signature_type": "Line",
"id": "CVE-2026-33977-1f80f933",
"deprecated": false,
"source": "https://github.com/freerdp/freerdp/commit/9be3f03d94a50892fd58a9f7dee72b2313c69b47",
"target": {
"file": "libfreerdp/codec/dsp.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"313059719051168953279981321621284631172",
"1608208887809092689858395632213707287",
"266691875119607533276273676915890765709",
"58203710151291557414018479213843120754",
"205705319832954602913746864351500691293",
"167373129491020828174094741663516011435",
"81115201060302679625618861278598527278",
"213465713407387026022579136565158143067",
"300802015265203590247439580603835968284",
"90375194995024105971758591989173538760",
"134198277461091868160743266217724947589",
"11226862666982207573501972149902201389",
"177772214160195408621174319205105493316",
"331415897967591359797777520630678136778",
"190551798074234161013278261547298941486",
"124309392823400985434997162403683313739",
"291069044997322580593112420370347525043",
"47800664452044214651402955194286039763",
"322490403405468343914317455954834869766",
"95433370875425295832012757529772309913",
"173740166329223149998206452018511193413",
"81115201060302679625618861278598527278",
"223645821899158928400802442633796775230",
"260804351523069384712465389180794192958",
"240452525504598402049089717207176161450"
]
},
"signature_version": "v1"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-33977.json"
"2026-07-15T00:14:23Z"