security: Check HMAC on non-FIPS fastpath input

CVE-2026-32105: Add a check that the HMAC signature supplied with a
non-FIPS fastpath input PDU matches the calculated signature.
This commit is contained in:
matt335672
2026-03-10 20:38:50 +00:00
parent 759104912c
commit 187d22cef8
+7 -1
View File
@@ -1149,8 +1149,14 @@ xrdp_sec_recv_fastpath(struct xrdp_sec *self, struct stream *s)
return 1; return 1;
} }
/* remainder of TS_FP_INPUT_PDU */ /* remainder of TS_FP_INPUT_PDU */
in_uint8s(s, 8); /* dataSignature (8 bytes), skip for now */ in_uint8p(s, data_signature, 8);
xrdp_sec_decrypt(self, s->p, (int)(s->end - s->p)); xrdp_sec_decrypt(self, s->p, (int)(s->end - s->p));
if (!xrdp_sec_check_sig(self, data_signature, 8,
s->p, (int)(s->end - s->p)))
{
LOG(LOG_LEVEL_ERROR, "MAC checksum error for FP-non-FIPS PDU");
return 1;
}
} }
} }