CVE-2026-35512: Heap overflow in dynvc processing
Length checking for the EGFX dynamic virtual channel is inadequate, allowing for heap overflows to be forced by a malicious client before authentication.
This commit is contained in:
+10
-1
@@ -468,6 +468,15 @@ drdynvc_process_data_first(struct xrdp_channel *self,
|
||||
"ChannelId %d, Length %d, Data (omitted from the log)",
|
||||
chan_id, total_bytes);
|
||||
|
||||
// See [MS-RDPBCGR] 2.2.3
|
||||
if (total_bytes < 1590 || bytes > total_bytes)
|
||||
{
|
||||
LOG(LOG_LEVEL_ERROR,
|
||||
"Badly formed DYNVC_DATA_FIRST PDU received on dynamic channel %d",
|
||||
chan_id);
|
||||
return 1;
|
||||
}
|
||||
|
||||
session = self->sec_layer->rdp_layer->session;
|
||||
if (chan_id > 255)
|
||||
{
|
||||
@@ -513,7 +522,7 @@ drdynvc_process_data(struct xrdp_channel *self,
|
||||
session = self->sec_layer->rdp_layer->session;
|
||||
if (chan_id > 255)
|
||||
{
|
||||
LOG(LOG_LEVEL_ERROR, "Received message for an invalid "
|
||||
LOG(LOG_LEVEL_ERROR, "Received DYNVC_DATA PDU for an invalid "
|
||||
"channel id. channel id %d", chan_id);
|
||||
return 1;
|
||||
}
|
||||
|
||||
+6
-3
@@ -968,10 +968,12 @@ xrdp_egfx_data_first(struct xrdp_process *id, int chan_id,
|
||||
egfx = id->wm->mm->egfx;
|
||||
if (egfx->s != NULL)
|
||||
{
|
||||
LOG(LOG_LEVEL_DEBUG, "xrdp_egfx_data_first: Error!"
|
||||
" Stream is not working on initial data received!");
|
||||
LOG(LOG_LEVEL_ERROR, "DYNVC_DATA_FIRST PDU received while"
|
||||
" another stream is active on channel %d", chan_id);
|
||||
return 1;
|
||||
}
|
||||
make_stream(egfx->s);
|
||||
// Caller has checked total_bytes is >= 0 and bytes is < total_bytes
|
||||
init_stream(egfx->s, total_bytes);
|
||||
out_uint8a(egfx->s, data, bytes);
|
||||
return 0;
|
||||
@@ -1024,7 +1026,8 @@ xrdp_egfx_data(struct xrdp_process *id, int chan_id, char *data, int bytes)
|
||||
}
|
||||
if (!s_check_rem_out(egfx->s, bytes))
|
||||
{
|
||||
LOG(LOG_LEVEL_DEBUG, "xrdp_egfx_data: error");
|
||||
LOG(LOG_LEVEL_ERROR, "DYNVC_DATA PDU data overflow on channel %d",
|
||||
chan_id);
|
||||
return 1;
|
||||
}
|
||||
out_uint8a(egfx->s, data, bytes);
|
||||
|
||||
Reference in New Issue
Block a user