CVE Vulnerabilities

CVE-2024-32040

Integer Underflow (Wrap or Wraparound)

Published: Apr 22, 2024 | Modified: Nov 03, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 and have connections to servers using the NSC codec are vulnerable to integer underflow. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, do not use the NSC codec (e.g. use -nsc).

Weakness

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

Affected Software

NameVendorStart VersionEnd Version
FreerdpFreerdp*2.11.6 (excluding)
FreerdpFreerdp3.0.0 (including)3.5.0 (excluding)
Red Hat Enterprise Linux 9RedHatfreerdp-2:2.11.7-1.el9*
Freerdp2Ubuntuesm-apps/noble*
Freerdp2Ubuntuesm-infra/focal*
Freerdp2Ubuntufocal*
Freerdp2Ubuntujammy*
Freerdp2Ubuntumantic*
Freerdp2Ubuntunoble*
Freerdp2Ubuntuoracular*
Freerdp2Ubuntuupstream*
Freerdp3Ubuntudevel*
Freerdp3Ubuntunoble*
Freerdp3Ubuntuoracular*
Freerdp3Ubuntuplucky*
Freerdp3Ubuntuquesting*
Freerdp3Ubuntuupstream*

References