Fix for DYNVC Multi-Chunk Reassembly Logic Defects

This commit is contained in:
Denis Skvortsov
2026-07-15 17:24:30 +03:00
parent 3af31df3fc
commit b824c93b86
+8 -5
View File
@@ -18,6 +18,7 @@
* channel layer
*/
#include "parse.h"
#if defined(HAVE_CONFIG_H)
#include <config_ac.h>
#endif
@@ -610,6 +611,8 @@ xrdp_channel_process_drdynvc(struct xrdp_channel *self,
}
out_uint8a(self->s, s->p, length); /* append data to chunk buffer */
in_uint8s(s, length); /* virtualChannelData */
s_mark_end(self->s);
self->s->p = self->s->data;
ls = self->s;
break;
case 3: /* CHANNEL_FLAG_FIRST and CHANNEL_FLAG_LAST */
@@ -635,19 +638,19 @@ xrdp_channel_process_drdynvc(struct xrdp_channel *self,
switch (cmd & 0xf0)
{
case CMD_DVC_CAPABILITY:
rv = drdynvc_process_capability_response(self, cmd, s);
rv = drdynvc_process_capability_response(self, cmd, ls);
break;
case CMD_DVC_OPEN_CHANNEL:
rv = drdynvc_process_open_channel_response(self, cmd, s);
rv = drdynvc_process_open_channel_response(self, cmd, ls);
break;
case CMD_DVC_CLOSE_CHANNEL:
rv = drdynvc_process_close_channel_response(self, cmd, s);
rv = drdynvc_process_close_channel_response(self, cmd, ls);
break;
case CMD_DVC_DATA_FIRST:
rv = drdynvc_process_data_first(self, cmd, s);
rv = drdynvc_process_data_first(self, cmd, ls);
break;
case CMD_DVC_DATA:
rv = drdynvc_process_data(self, cmd, s);
rv = drdynvc_process_data(self, cmd, ls);
break;
default:
LOG(LOG_LEVEL_ERROR, "Received header [MS-RDPEDYC] with "