CVE-2026-55645: OOB read in Client Control PDU processing
This commit is contained in:
@@ -1157,6 +1157,10 @@ xrdp_rdp_process_data_control(struct xrdp_rdp *self, struct stream *s)
|
|||||||
{
|
{
|
||||||
int action;
|
int action;
|
||||||
|
|
||||||
|
if (!s_check_rem_and_log(s, 8, "Parsing [MS-RDPBCGR] TS_CONTROL_PDU"))
|
||||||
|
{
|
||||||
|
return 1;
|
||||||
|
}
|
||||||
in_uint16_le(s, action);
|
in_uint16_le(s, action);
|
||||||
in_uint8s(s, 2); /* user id */
|
in_uint8s(s, 2); /* user id */
|
||||||
in_uint8s(s, 4); /* control id */
|
in_uint8s(s, 4); /* control id */
|
||||||
|
|||||||
Reference in New Issue
Block a user