Fix for DYNVC Multi-Chunk Reassembly Logic Defects

This commit is contained in:
Denis Skvortsov
2026-07-15 17:24:30 +03:00
parent 3af31df3fc
commit b824c93b86
+8 -5
View File
@@ -18,6 +18,7 @@
* channel layer * channel layer
*/ */
#include "parse.h"
#if defined(HAVE_CONFIG_H) #if defined(HAVE_CONFIG_H)
#include <config_ac.h> #include <config_ac.h>
#endif #endif
@@ -610,6 +611,8 @@ xrdp_channel_process_drdynvc(struct xrdp_channel *self,
} }
out_uint8a(self->s, s->p, length); /* append data to chunk buffer */ out_uint8a(self->s, s->p, length); /* append data to chunk buffer */
in_uint8s(s, length); /* virtualChannelData */ in_uint8s(s, length); /* virtualChannelData */
s_mark_end(self->s);
self->s->p = self->s->data;
ls = self->s; ls = self->s;
break; break;
case 3: /* CHANNEL_FLAG_FIRST and CHANNEL_FLAG_LAST */ case 3: /* CHANNEL_FLAG_FIRST and CHANNEL_FLAG_LAST */
@@ -635,19 +638,19 @@ xrdp_channel_process_drdynvc(struct xrdp_channel *self,
switch (cmd & 0xf0) switch (cmd & 0xf0)
{ {
case CMD_DVC_CAPABILITY: case CMD_DVC_CAPABILITY:
rv = drdynvc_process_capability_response(self, cmd, s); rv = drdynvc_process_capability_response(self, cmd, ls);
break; break;
case CMD_DVC_OPEN_CHANNEL: case CMD_DVC_OPEN_CHANNEL:
rv = drdynvc_process_open_channel_response(self, cmd, s); rv = drdynvc_process_open_channel_response(self, cmd, ls);
break; break;
case CMD_DVC_CLOSE_CHANNEL: case CMD_DVC_CLOSE_CHANNEL:
rv = drdynvc_process_close_channel_response(self, cmd, s); rv = drdynvc_process_close_channel_response(self, cmd, ls);
break; break;
case CMD_DVC_DATA_FIRST: case CMD_DVC_DATA_FIRST:
rv = drdynvc_process_data_first(self, cmd, s); rv = drdynvc_process_data_first(self, cmd, ls);
break; break;
case CMD_DVC_DATA: case CMD_DVC_DATA:
rv = drdynvc_process_data(self, cmd, s); rv = drdynvc_process_data(self, cmd, ls);
break; break;
default: default:
LOG(LOG_LEVEL_ERROR, "Received header [MS-RDPEDYC] with " LOG(LOG_LEVEL_ERROR, "Received header [MS-RDPEDYC] with "