CVE-2026-33516 : Address potential OOB read

The codec list processing code contains a potential out-of-bounds
read, as the length check comes after the data is read.
This commit is contained in:
matt335672
2026-04-02 11:23:42 +01:00
parent 2dfe8bbce2
commit 6831249bed
+9 -8
View File
@@ -599,26 +599,27 @@ xrdp_caps_process_codecs(struct xrdp_rdp *self, struct stream *s, int len)
{
codec_guid = s->p;
g_memcpy(guid.g, s->p, GUID_SIZE);
guid_to_str(&guid, codec_guid_str);
if (len < 16 + 1 + 2)
if (len < GUID_SIZE + 1 + 2)
{
LOG(LOG_LEVEL_ERROR, "xrdp_caps_process_codecs: error");
LOG(LOG_LEVEL_ERROR, "Short codec data received");
return 1;
}
in_uint8s(s, 16);
in_uint8a(s, guid.g, GUID_SIZE);
in_uint8(s, codec_id);
in_uint16_le(s, codec_properties_length);
len -= 16 + 1 + 2;
len -= GUID_SIZE + 1 + 2;
if (len < codec_properties_length)
{
LOG(LOG_LEVEL_ERROR, "xrdp_caps_process_codecs: error");
LOG(LOG_LEVEL_ERROR, "Short codec properties");
return 1;
}
len -= codec_properties_length;
next_guid = s->p + codec_properties_length;
guid_to_str(&guid, codec_guid_str);
if (g_memcmp(codec_guid, XR_CODEC_GUID_NSCODEC, 16) == 0)
{
LOG(LOG_LEVEL_INFO, "xrdp_caps_process_codecs: NSCodec(%s), codec id [%d], properties len [%d]",