Merge commit from fork
CVE-2026-41252: lib_palette_update Heap Buffer Overflow
This commit is contained in:
@@ -1649,6 +1649,13 @@ lib_palette_update(struct vnc *v)
|
||||
in_uint8s(s, 1);
|
||||
in_uint16_be(s, first_color);
|
||||
in_uint16_be(s, num_colors);
|
||||
if ((first_color + num_colors) > VNC_PALETTE_SIZE)
|
||||
{
|
||||
LOG(LOG_LEVEL_ERROR, "lib_palette_update: palette overflow");
|
||||
free_stream(s);
|
||||
return 1;
|
||||
}
|
||||
|
||||
init_stream(s, 8192);
|
||||
error = trans_force_read_s(v->trans, s, num_colors * 6);
|
||||
}
|
||||
|
||||
@@ -76,6 +76,8 @@ struct xrdp_client_info;
|
||||
/* Defined in vnc_clip.c */
|
||||
struct vnc_clipboard_data;
|
||||
|
||||
#define VNC_PALETTE_SIZE 256
|
||||
|
||||
/* Defined in xrdp_client_info.h */
|
||||
struct monitor_info;
|
||||
|
||||
@@ -167,7 +169,7 @@ struct vnc
|
||||
int server_bpp;
|
||||
char mod_name[256];
|
||||
int mod_mouse_state;
|
||||
int palette[256];
|
||||
int palette[VNC_PALETTE_SIZE];
|
||||
int vnc_desktop;
|
||||
char username[256];
|
||||
char password[256];
|
||||
|
||||
Reference in New Issue
Block a user