CVE-2026-41252: lib_palette_update Heap Buffer Overflow

This commit is contained in:
matt335672
2026-04-15 10:50:10 +01:00
parent c3788a374a
commit 9834a58ca6
2 changed files with 10 additions and 1 deletions
+7
View File
@@ -1618,6 +1618,13 @@ lib_palette_update(struct vnc *v)
in_uint8s(s, 1); in_uint8s(s, 1);
in_uint16_be(s, first_color); in_uint16_be(s, first_color);
in_uint16_be(s, num_colors); in_uint16_be(s, num_colors);
if ((first_color + num_colors) > VNC_PALETTE_SIZE)
{
LOG(LOG_LEVEL_ERROR, "lib_palette_update: palette overflow");
free_stream(s);
return 1;
}
init_stream(s, 8192); init_stream(s, 8192);
error = trans_force_read_s(v->trans, s, num_colors * 6); error = trans_force_read_s(v->trans, s, num_colors * 6);
} }
+3 -1
View File
@@ -76,6 +76,8 @@ struct xrdp_client_info;
/* Defined in vnc_clip.c */ /* Defined in vnc_clip.c */
struct vnc_clipboard_data; struct vnc_clipboard_data;
#define VNC_PALETTE_SIZE 256
/* Defined in xrdp_client_info.h */ /* Defined in xrdp_client_info.h */
struct monitor_info; struct monitor_info;
@@ -167,7 +169,7 @@ struct vnc
int server_bpp; int server_bpp;
char mod_name[256]; char mod_name[256];
int mod_mouse_state; int mod_mouse_state;
int palette[256]; int palette[VNC_PALETTE_SIZE];
int vnc_desktop; int vnc_desktop;
char username[256]; char username[256];
char password[256]; char password[256];