Merge commit from fork

CVE-2026-41252: lib_palette_update Heap Buffer Overflow
This commit is contained in:
metalefty
2026-07-02 17:33:45 +09:00
committed by GitHub
3 changed files with 40 additions and 27 deletions
+7
View File
@@ -1649,6 +1649,13 @@ lib_palette_update(struct vnc *v)
in_uint8s(s, 1); in_uint8s(s, 1);
in_uint16_be(s, first_color); in_uint16_be(s, first_color);
in_uint16_be(s, num_colors); in_uint16_be(s, num_colors);
if ((first_color + num_colors) > VNC_PALETTE_SIZE)
{
LOG(LOG_LEVEL_ERROR, "lib_palette_update: palette overflow");
free_stream(s);
return 1;
}
init_stream(s, 8192); init_stream(s, 8192);
error = trans_force_read_s(v->trans, s, num_colors * 6); error = trans_force_read_s(v->trans, s, num_colors * 6);
} }
+3 -1
View File
@@ -76,6 +76,8 @@ struct xrdp_client_info;
/* Defined in vnc_clip.c */ /* Defined in vnc_clip.c */
struct vnc_clipboard_data; struct vnc_clipboard_data;
#define VNC_PALETTE_SIZE 256
/* Defined in xrdp_client_info.h */ /* Defined in xrdp_client_info.h */
struct monitor_info; struct monitor_info;
@@ -167,7 +169,7 @@ struct vnc
int server_bpp; int server_bpp;
char mod_name[256]; char mod_name[256];
int mod_mouse_state; int mod_mouse_state;
int palette[256]; int palette[VNC_PALETTE_SIZE];
int vnc_desktop; int vnc_desktop;
char username[256]; char username[256];
char password[256]; char password[256];
+30 -26
View File
@@ -298,33 +298,37 @@ port=-1
#disabled_encodings_mask=0 #disabled_encodings_mask=0
; Generic VNC Proxy ; Generic VNC Proxy
; Tailor this to specific hosts and VNC instances by specifying an ip ; To use this, remove the '#-#' prefix from the lines below. Tailor
; the section to specific hosts and VNC instances by specifying an ip
; and port and setting a suitable name. ; and port and setting a suitable name.
[vnc-any] ; This can be used with no customisations in test environments, but
name=vnc-any ; should always be locked down to specific hosts and/or ports in
lib=libvnc.@lib_extension@ ; production.
ip=ask #-#[vnc-any]
port=ask5900 #-#name=vnc-any
username=na #-#lib=libvnc.@lib_extension@
password=ask #-#ip=ask
#pamusername=asksame #-#port=ask5900
#pampassword=asksame #-#username=na
#delay_ms=2000 #-#password=ask
; Use one of these to connect to a chansrv instance created outside of sesman #-##pamusername=asksame
; (e.g. as part of an x11vnc console session). Replace 's' with the #-##pampassword=asksame
; display string of the session, and (if applicable) 'u' with the numeric #-##delay_ms=2000
; UID of the session. #-#; Use one of these to connect to a chansrv instance created outside of sesman
; #-#; (e.g. as part of an x11vnc console session). Replace 's' with the
; For compatibility, a completely numeric display string is taken to be #-#; display string of the session, and (if applicable) 'u' with the numeric
; an X11 display number #-#; UID of the session.
; #-#;
; You will also need to change the value of SessionSockdirGroup in #-#; For compatibility, a completely numeric display string is taken to be
; sesman.ini to allow xrdp to reach the chansrv instance #-#; an X11 display number
; #-#;
; If 'username' or 'pamusername' is set, you probably don't need to use #-#; You will also need to change the value of SessionSockdirGroup in
; the two parameter variant with 'u'. #-#; sesman.ini to allow xrdp to reach the chansrv instance
#chansrvport=DISPLAY(n) #-#;
#chansrvport=DISPLAY(n,u) #-#; If 'username' or 'pamusername' is set, you probably don't need to use
#-#; the two parameter variant with 'u'.
#-##chansrvport=DISPLAY(n)
#-##chansrvport=DISPLAY(n,u)
; Generic RDP proxy using NeutrinoRDP ; Generic RDP proxy using NeutrinoRDP
; Tailor this to specific hosts by specifying an ip and port and setting ; Tailor this to specific hosts by specifying an ip and port and setting