FreeRDP has released version 3.31.0, a major security and stability update that fixes 22 disclosed vulnerabilities in the widely deployed open-source implementation of the Remote Desktop Protocol (RDP).
Project maintainers described the release as a “huge bugfix and security release” and urged distributors to update as soon as possible due to the severity of the issues it addresses.
The update is significant for organizations using FreeRDP in Linux desktop environments, remote-access clients, thin clients, RDP gateways, virtualization consoles, embedded systems, and application delivery products.
FreeRDP 3.31.0 Fixes 22 Security Flaws
The release resolves multiple memory-safety weaknesses, including a heap overflow flaw, as well as pre-authentication denial-of-service vulnerabilities.
Pre-authentication bugs are particularly important because an unauthenticated attacker may be able to crash or disrupt an exposed RDP-facing service before a legitimate user completes the login process.
Memory-corruption vulnerabilities present a different class of risk. Depending on the affected component, exploitability, and runtime defenses, flaws such as heap overflows may result in application crashes, information disclosure, or potentially code execution.
The FreeRDP project has not publicly detailed every individual vulnerability in its short release announcement, but it published links to 22 associated security advisories.
FreeRDP is used in both RDP client and server implementations and includes functionality for protocol negotiation, Network Level Authentication (NLA), graphics rendering, virtual channels, device and printer redirection, smart card support, clipboard sharing, audio, and RDP Gateway communication.
This means the practical impact is not limited to desktop users: a malicious RDP server could target a vulnerable client, while an exposed server, proxy, or gateway may process hostile network traffic from untrusted remote users.
Among the fixes, FreeRDP developers bounded AVC444v2 chroma processing to the decoded frame width, restricted NTLM data copying to the smaller input entity, enforced a minimum 16-byte signature buffer before access, and limited RDP Gateway authorization-tunnel responses to the received data length.
The update also addresses use-after-free conditions associated with printer drivers, improves reallocation handling, introduces additional null-pointer checks, and strengthens stream validation.
Akallabeth further resolved race conditions affecting RemoteApp Integrated Locally (RAIL) and dynamic-channel processing.
Collectively, these changes reflect common defensive priorities in RDP software: strict validation of attacker-controlled lengths, safe memory ownership, correct buffer boundaries, and resilient handling of asynchronous protocol events.
Version 3.31.0 also delivers compatibility and performance improvements. FreeRDP said an optimized YUV decoder should provide faster client graphics during AVC/H.264 sessions.
The release additionally expands hardware-decoder support and uses dav1d for AV1 decoding, while addressing OpenSSL BIO/SSL creation failures, TLS AEAD data-limit settings, Android clipboard behavior, excessive CPU use in the SDL client, and build issues affecting OpenBSD, Cygwin, MinGW, and BSD platforms.
Administrators should inventory installed FreeRDP packages, including libraries bundled within third-party remote-access products, and obtain patched builds from their operating-system distributor or the official FreeRDP release channel.
Priority testing should cover internet-facing gateways, shared workstations, graphics-intensive RDP deployments, and systems that use device-redirection features.
Where immediate patching is not possible, organizations should reduce RDP exposure through network segmentation, VPN or zero-trust access controls, IP allowlisting, and monitoring for service crashes or anomalous connection attempts.
Give your security team the visibility and context to investigate suspicious activity faster and contain threats before business impact grows. Strengthen Your Investigations with ANY.RUN