From 9834a58ca65018d09b04ed7550dfa71aecb09b10 Mon Sep 17 00:00:00 2001 From: matt335672 <30179339+matt335672@users.noreply.github.com> Date: Wed, 15 Apr 2026 10:50:10 +0100 Subject: [PATCH 1/2] CVE-2026-41252: lib_palette_update Heap Buffer Overflow --- vnc/vnc.c | 7 +++++++ vnc/vnc.h | 4 +++- 2 files changed, 10 insertions(+), 1 deletion(-) diff --git a/vnc/vnc.c b/vnc/vnc.c index 298e2d6c..ac5d5c30 100644 --- a/vnc/vnc.c +++ b/vnc/vnc.c @@ -1618,6 +1618,13 @@ lib_palette_update(struct vnc *v) in_uint8s(s, 1); in_uint16_be(s, first_color); in_uint16_be(s, num_colors); + if ((first_color + num_colors) > VNC_PALETTE_SIZE) + { + LOG(LOG_LEVEL_ERROR, "lib_palette_update: palette overflow"); + free_stream(s); + return 1; + } + init_stream(s, 8192); error = trans_force_read_s(v->trans, s, num_colors * 6); } diff --git a/vnc/vnc.h b/vnc/vnc.h index d2fd9bb6..0b78f433 100644 --- a/vnc/vnc.h +++ b/vnc/vnc.h @@ -76,6 +76,8 @@ struct xrdp_client_info; /* Defined in vnc_clip.c */ struct vnc_clipboard_data; +#define VNC_PALETTE_SIZE 256 + /* Defined in xrdp_client_info.h */ struct monitor_info; @@ -167,7 +169,7 @@ struct vnc int server_bpp; char mod_name[256]; int mod_mouse_state; - int palette[256]; + int palette[VNC_PALETTE_SIZE]; int vnc_desktop; char username[256]; char password[256]; From a85e108cdf085de1822473400a81f2a2d6a0dafd Mon Sep 17 00:00:00 2001 From: matt335672 <30179339+matt335672@users.noreply.github.com> Date: Wed, 15 Apr 2026 10:58:49 +0100 Subject: [PATCH 2/2] xrdp.ini: Remove [vnc-any] as a default section As it stands, this is not suitable for production environments, as the attached CVE shows. --- xrdp/xrdp.ini.in | 56 ++++++++++++++++++++++++++---------------------- 1 file changed, 30 insertions(+), 26 deletions(-) diff --git a/xrdp/xrdp.ini.in b/xrdp/xrdp.ini.in index b0a71a54..eff86266 100644 --- a/xrdp/xrdp.ini.in +++ b/xrdp/xrdp.ini.in @@ -298,33 +298,37 @@ port=-1 #disabled_encodings_mask=0 ; Generic VNC Proxy -; Tailor this to specific hosts and VNC instances by specifying an ip +; To use this, remove the '#-#' prefix from the lines below. Tailor +; the section to specific hosts and VNC instances by specifying an ip ; and port and setting a suitable name. -[vnc-any] -name=vnc-any -lib=libvnc.@lib_extension@ -ip=ask -port=ask5900 -username=na -password=ask -#pamusername=asksame -#pampassword=asksame -#delay_ms=2000 -; Use one of these to connect to a chansrv instance created outside of sesman -; (e.g. as part of an x11vnc console session). Replace 's' with the -; display string of the session, and (if applicable) 'u' with the numeric -; UID of the session. -; -; For compatibility, a completely numeric display string is taken to be -; an X11 display number -; -; You will also need to change the value of SessionSockdirGroup in -; sesman.ini to allow xrdp to reach the chansrv instance -; -; If 'username' or 'pamusername' is set, you probably don't need to use -; the two parameter variant with 'u'. -#chansrvport=DISPLAY(n) -#chansrvport=DISPLAY(n,u) +; This can be used with no customisations in test environments, but +; should always be locked down to specific hosts and/or ports in +; production. +#-#[vnc-any] +#-#name=vnc-any +#-#lib=libvnc.@lib_extension@ +#-#ip=ask +#-#port=ask5900 +#-#username=na +#-#password=ask +#-##pamusername=asksame +#-##pampassword=asksame +#-##delay_ms=2000 +#-#; Use one of these to connect to a chansrv instance created outside of sesman +#-#; (e.g. as part of an x11vnc console session). Replace 's' with the +#-#; display string of the session, and (if applicable) 'u' with the numeric +#-#; UID of the session. +#-#; +#-#; For compatibility, a completely numeric display string is taken to be +#-#; an X11 display number +#-#; +#-#; You will also need to change the value of SessionSockdirGroup in +#-#; sesman.ini to allow xrdp to reach the chansrv instance +#-#; +#-#; If 'username' or 'pamusername' is set, you probably don't need to use +#-#; the two parameter variant with 'u'. +#-##chansrvport=DISPLAY(n) +#-##chansrvport=DISPLAY(n,u) ; Generic RDP proxy using NeutrinoRDP ; Tailor this to specific hosts by specifying an ip and port and setting