Merge commit from fork

CVE-2026-41252: lib_palette_update Heap Buffer Overflow
This commit is contained in:
metalefty
2026-07-02 17:33:45 +09:00
committed by GitHub
3 changed files with 40 additions and 27 deletions
+7
View File
@@ -1649,6 +1649,13 @@ lib_palette_update(struct vnc *v)
in_uint8s(s, 1);
in_uint16_be(s, first_color);
in_uint16_be(s, num_colors);
if ((first_color + num_colors) > VNC_PALETTE_SIZE)
{
LOG(LOG_LEVEL_ERROR, "lib_palette_update: palette overflow");
free_stream(s);
return 1;
}
init_stream(s, 8192);
error = trans_force_read_s(v->trans, s, num_colors * 6);
}
+3 -1
View File
@@ -76,6 +76,8 @@ struct xrdp_client_info;
/* Defined in vnc_clip.c */
struct vnc_clipboard_data;
#define VNC_PALETTE_SIZE 256
/* Defined in xrdp_client_info.h */
struct monitor_info;
@@ -167,7 +169,7 @@ struct vnc
int server_bpp;
char mod_name[256];
int mod_mouse_state;
int palette[256];
int palette[VNC_PALETTE_SIZE];
int vnc_desktop;
char username[256];
char password[256];
+30 -26
View File
@@ -298,33 +298,37 @@ port=-1
#disabled_encodings_mask=0
; Generic VNC Proxy
; Tailor this to specific hosts and VNC instances by specifying an ip
; To use this, remove the '#-#' prefix from the lines below. Tailor
; the section to specific hosts and VNC instances by specifying an ip
; and port and setting a suitable name.
[vnc-any]
name=vnc-any
lib=libvnc.@lib_extension@
ip=ask
port=ask5900
username=na
password=ask
#pamusername=asksame
#pampassword=asksame
#delay_ms=2000
; Use one of these to connect to a chansrv instance created outside of sesman
; (e.g. as part of an x11vnc console session). Replace 's' with the
; display string of the session, and (if applicable) 'u' with the numeric
; UID of the session.
;
; For compatibility, a completely numeric display string is taken to be
; an X11 display number
;
; You will also need to change the value of SessionSockdirGroup in
; sesman.ini to allow xrdp to reach the chansrv instance
;
; If 'username' or 'pamusername' is set, you probably don't need to use
; the two parameter variant with 'u'.
#chansrvport=DISPLAY(n)
#chansrvport=DISPLAY(n,u)
; This can be used with no customisations in test environments, but
; should always be locked down to specific hosts and/or ports in
; production.
#-#[vnc-any]
#-#name=vnc-any
#-#lib=libvnc.@lib_extension@
#-#ip=ask
#-#port=ask5900
#-#username=na
#-#password=ask
#-##pamusername=asksame
#-##pampassword=asksame
#-##delay_ms=2000
#-#; Use one of these to connect to a chansrv instance created outside of sesman
#-#; (e.g. as part of an x11vnc console session). Replace 's' with the
#-#; display string of the session, and (if applicable) 'u' with the numeric
#-#; UID of the session.
#-#;
#-#; For compatibility, a completely numeric display string is taken to be
#-#; an X11 display number
#-#;
#-#; You will also need to change the value of SessionSockdirGroup in
#-#; sesman.ini to allow xrdp to reach the chansrv instance
#-#;
#-#; If 'username' or 'pamusername' is set, you probably don't need to use
#-#; the two parameter variant with 'u'.
#-##chansrvport=DISPLAY(n)
#-##chansrvport=DISPLAY(n,u)
; Generic RDP proxy using NeutrinoRDP
; Tailor this to specific hosts by specifying an ip and port and setting