From 6831249bed8785c9f6cbbdf0dcddaad597705832 Mon Sep 17 00:00:00 2001 From: matt335672 <30179339+matt335672@users.noreply.github.com> Date: Thu, 2 Apr 2026 11:23:42 +0100 Subject: [PATCH] CVE-2026-33516 : Address potential OOB read The codec list processing code contains a potential out-of-bounds read, as the length check comes after the data is read. --- libxrdp/xrdp_caps.c | 17 +++++++++-------- 1 file changed, 9 insertions(+), 8 deletions(-) diff --git a/libxrdp/xrdp_caps.c b/libxrdp/xrdp_caps.c index 966773e3..acff9199 100644 --- a/libxrdp/xrdp_caps.c +++ b/libxrdp/xrdp_caps.c @@ -599,26 +599,27 @@ xrdp_caps_process_codecs(struct xrdp_rdp *self, struct stream *s, int len) { codec_guid = s->p; - g_memcpy(guid.g, s->p, GUID_SIZE); - guid_to_str(&guid, codec_guid_str); - - if (len < 16 + 1 + 2) + if (len < GUID_SIZE + 1 + 2) { - LOG(LOG_LEVEL_ERROR, "xrdp_caps_process_codecs: error"); + LOG(LOG_LEVEL_ERROR, "Short codec data received"); return 1; } - in_uint8s(s, 16); + + in_uint8a(s, guid.g, GUID_SIZE); in_uint8(s, codec_id); in_uint16_le(s, codec_properties_length); - len -= 16 + 1 + 2; + len -= GUID_SIZE + 1 + 2; + if (len < codec_properties_length) { - LOG(LOG_LEVEL_ERROR, "xrdp_caps_process_codecs: error"); + LOG(LOG_LEVEL_ERROR, "Short codec properties"); return 1; } len -= codec_properties_length; next_guid = s->p + codec_properties_length; + guid_to_str(&guid, codec_guid_str); + if (g_memcmp(codec_guid, XR_CODEC_GUID_NSCODEC, 16) == 0) { LOG(LOG_LEVEL_INFO, "xrdp_caps_process_codecs: NSCodec(%s), codec id [%d], properties len [%d]",