Commit Graph

5350 Commits

Author SHA1 Message Date
matt335672 53bc57cf59 security: Exit on failure of env_set_user()
CVE-2026-32107. Prevent possible privilege escalation if setuid()
fails.
2026-04-14 11:52:28 +01:00
metalefty 7738d111d5 Merge commit from fork
CVE-2026-35512: Heap overflow in dynvc processing
2026-04-14 17:00:20 +09:00
metalefty 084eb2237e Merge commit from fork
CVE-2026-33689: Fix length check on channel open
2026-04-14 16:43:27 +09:00
metalefty 2e465c0b3a Merge commit from fork
CVE-2026-33145: Default AllowAlternateShell to 'no'
2026-04-14 15:14:20 +09:00
metalefty 16c971a437 Merge commit from fork
security: vulns in neutrinordp fragment reassembly
2026-04-14 15:07:03 +09:00
metalefty 6d1f89a919 Merge commit from fork
CVE-2026-33516 : Address potential OOB read
2026-04-14 15:01:23 +09:00
metalefty 1bacf22fb7 Merge commit from fork
Check HMAC values when non-TLS connections are used
2026-04-14 14:06:45 +09:00
metalefty 220a50b1d2 Merge commit from fork
CVE-2026-32624: buffer overflow if domain sep used
2026-04-14 09:30:27 +09:00
jsorg71 832edcab20 Merge pull request #3779 from jsorg71/instfiles_err
remove keymap file before creating sym link
2026-04-06 12:05:57 -07:00
Jay Sorg 05210adb22 use -f when creating sym link 2026-04-06 10:29:17 -07:00
matt335672 99dfacfffc Merge pull request #3755 from matt335672/gfx_resize
resizing: Simplify GFX resizing
2026-04-06 12:46:46 +01:00
matt335672 41a4af0a36 CVE-2026-35512: Heap overflow in dynvc processing
Length checking for the EGFX dynamic virtual channel is inadequate,
allowing for heap overflows to be forced by a malicious client before
authentication.
2026-04-06 12:39:32 +01:00
matt335672 6831249bed CVE-2026-33516 : Address potential OOB read
The codec list processing code contains a potential out-of-bounds
read, as the length check comes after the data is read.
2026-04-02 11:23:42 +01:00
matt335672 8e5875e438 Merge pull request #3777 from gpotter2/rename-rdpflags
Rename RDP_INFO flags to spec names
2026-04-01 09:17:57 +01:00
gpotter2 42b830f124 Rename RDP_INFO flags to spec names, add missing 2026-03-31 21:22:33 +02:00
matt335672 36fbebcb9d Merge pull request #3768 from matt335672/remove_unused_auth
sesman: Remove unused authentication methods
2026-03-26 17:55:48 +00:00
matt335672 1f34c4b37c Merge pull request #3767 from Kropyls/devel
g_tcp_connect ipv4/6 mixing fix
2026-03-23 18:23:10 +00:00
matt335672 3c131a9f5e CVE-2026-33689: Fix length check on channel open
A check for at least two bytes remaining in a buffer should be 4 bytes.
2026-03-23 17:38:38 +00:00
matt335672 8bfc79a0bc Update security reporting instructions in SECURITY.md
Clarified instructions for reporting security vulnerabilities and emphasized that the email address is not secure for such reports.
2026-03-23 14:41:33 +00:00
Matt Cunningham fcc5bd79ea g_tcp_connect fix:
- add addr_is_ipv4 helper function
- add addr_is_ipv6 helper function
- add get_socket_family helper function
- g_tcp_connect:
  - #define for MAX_PORT_STR length
  - create *addr_arg char that is used in getaddrinfo so we can do any last-minute changes directly
  - add chars host and service which are primarily used for debug logging of attempted connection points
  - calls get_socket_family to discover family of socket
  - add switch case logic for AF_INET6/4:
    - v4: just calls addr_is_ipv6 so we don't fail on a hostname input
    - v6: drop addrconfig flag and add AI_ALL so we can try to map ipv4 destinations against ipv6 socket to support varied configurations we could see
    - if an ipv4 address comes in against an ipv6 socket, we map it to try and connect anyways
  - getaddrinfo now calls addr_arg so it picks up changes that an ipv6-case may have done
  - before calling connect, use getnameinfo to get logging values for the actual host ip/port we are about to attempt a connect on - I found this useful when debugging so thought it had value to keep
- change if (res > -1) to if (res == 0): the bsd man pages for getaddrinfo only promise that it returns 0 on success, so it seems sensible to me to cover the event that an error code could be positive, which freebsd has some positive EAI_* errors based on this: https://github.com/freebsd/freebsd-src/blob/main/lib/libc/net/gai_strerror.c
- remove connect_loopback entirely:  this had several bits of logic handling ipv6 and ipv4 mixing already and ended up being redundant because of the restructuring of g_tcp_connect, which covers direct ip address char* inputs now
- add comment about OSX to IPv6 function for clarity
2026-03-23 08:21:29 -04:00
matt335672 0f2dc88541 sesman: Remove unused authentication methods
The Kerberos module and pam_userpass modules are now unused:

1) On all supported systems, PAM provides a far superior way to
   integrate Kerberos support.
2) The pam_userpass module (https://github.com/openwall/pam_userpass)
   (which is a lovely idea) is no longer maintained.
2026-03-23 11:24:19 +00:00
matt335672 b9742d94f7 Merge pull request #3764 from matt335672/regression_smartcard_removal
regression: Fix client issues with no smartcard
2026-03-18 20:24:05 +00:00
matt335672 7d618945b1 regression: Fix client issues with no smartcard
57609d4aa7 introduced an issue where
the numCapabilities field in the DR_CORE_CAPABILITY_REQ PDU
was incorrect unless --enable-smartcard was specified.

This commit also improves the logic around handling clients who
advertise a smartcard even if we do not support it.
2026-03-18 19:56:29 +00:00
matt335672 7f6e198b06 Merge pull request #3761 from matt335672/update_actions
CI: Upgrade to latest github action versions
2026-03-18 10:38:15 +00:00
matt335672 e2148a360c CI: Upgrade to latest github action versions
This has been prompted by the following deprecation messages:

> Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/cache@v4, actions/checkout@v4.
2026-03-18 09:53:46 +00:00
matt335672 45f62bdedd CVE-2026-33145: Default AllowAlternateShell to 'no' 2026-03-18 09:26:07 +00:00
matt335672 1737f19485 Merge pull request #3758 from matt335672/disable_smartcard_code
Disable smartcard code by default
2026-03-18 09:17:08 +00:00
matt335672 57609d4aa7 smartcard: Update redirector smartcard capability
Only announce a smartcard capability in the redirector if we can
support it.
2026-03-17 15:22:11 +00:00
matt335672 7a2ac0c177 security: Disable smartcard code by default
The smartcard code contains a number of security vulnerabilities and
does not work at the moment.

The code has been left in the source tree, but moved behind an
'--enable-smartcard' configure flag which is clearly marked as not
for production use.
2026-03-17 15:22:11 +00:00
matt335672 458944983f Merge pull request #3757 from matt335672/fix_audio_modules
regression: Audio modules
2026-03-16 11:13:03 +00:00
matt335672 3444f9a1e0 regression: Audio modules
Following on from the display number removal, the code to set
the environment variables for the audio modules has been discovered
to be incorrect.
2026-03-16 10:47:46 +00:00
matt335672 b73f0f1c75 Merge pull request #3753 from matt335672/display_num_regressions
regression: Display number related issues
2026-03-16 10:00:37 +00:00
matt335672 3f0f7df6ff CVE-2026-32623: vulns in neutrinordp fragment reassembly
This PR addresses potential buffer overflows in fragment reassembly in
the neutrinordp shim by adding length and status checks.
2026-03-14 11:28:19 +00:00
matt335672 f1a2bec415 CVE-2026-32624: buffer overflow if domain sep used
Check the username buffer is not overflowed if the domain separator
feature is used.
2026-03-13 17:08:14 +00:00
matt335672 a11ee461a7 resizing: Simplify GFX resizing
For GFX, we currently resize the client with a deactivation-reactivation
sequence. This is unnecessary, as the GFX RESET_GRAPHICS command does
all the work for us, and avoids the need to teardown and reestablish the
GFX channel.
2026-03-12 17:32:55 +00:00
matt335672 03b5d2cccb Code quality: Improve HMAC logging for security
The development logging for HMAC values is poor. Add a function to
make this a lot clearer.
2026-03-11 15:58:56 +00:00
matt335672 187d22cef8 security: Check HMAC on non-FIPS fastpath input
CVE-2026-32105: Add a check that the HMAC signature supplied with a
non-FIPS fastpath input PDU matches the calculated signature.
2026-03-11 15:58:41 +00:00
matt335672 759104912c security: Check HMAC on non-FIPS slowpath input
CVE-2026-32105: Add a check that the HMAC signature supplied with a
non-FIPS slowpath input PDU matches the calculated signature.
2026-03-11 15:58:19 +00:00
matt335672 0d8cf57e9d security: Check HMAC on FIPS slowpath input
CVE-2026-32105: Add a check that the HMAC signature supplied with a
FIPS slowpath input PDU matches the calculated signature.
2026-03-11 15:57:57 +00:00
matt335672 2a411f7525 security: Check HMAC on FIPS fastpath input
CVE-2026-32105: Add a check that the HMAC signature supplied with a
FIPS fastpath input PDU matches the calculated signature.
2026-03-11 15:56:55 +00:00
matt335672 defb1bcba4 regression: Display number related issues
The move away from the X11 display number has introduced a couple of regressions
1) XDG_SESSION_TYPE is not detected properly.

   pam_systemd.so contains code to map a PAM_TTY of ':n' to an 'x11'
   session type. This mapping is no longer done. We could re-introduce
   this code for X11, but there is no such code to detect a wayland
   display type. We try to fix this in a forward-looking way by setting
   XDG_SESSION_TYPE explicity before starting the PAM session.

2) utmp is not being updated correctly.

   The code for setting ut_id in the utmp[x] structure was setting the
   same value for all X11 displays, thus preventing utmp from being able
   to see more than one xrdp user

Also, an include is needed for sesman/eicp_process.c on some systems to
get access to strlcpy()
2026-03-11 13:17:33 +00:00
matt335672 90275daf6d Merge pull request #3747 from firewave/cppcheck-cv
enabled and fixed `constVariable` Cppcheck warnings
2026-03-06 11:01:56 +00:00
firewave 64154ea66d enabled and fixed constVariable Cppcheck warnings 2026-03-04 15:49:29 +01:00
matt335672 2dfe8bbce2 Merge pull request #3729 from matt335672/remove_display_num
Remove X11 display number from xrdp interfaces
2026-03-04 14:45:56 +00:00
matt335672 12102934b3 code quality: Address Copilot review comments 2026-03-04 14:34:34 +00:00
matt335672 0c92f5f5a2 xorgxrdp: Rename socket files 2026-03-04 14:34:34 +00:00
matt335672 c4727ad8f3 Replace X11 display number with a display string
As far as possible, use of the X11 display number is kept to
X11-specific routines. This is to make it easier to restructure
the code to add non-X11 display support.
2026-03-04 14:34:31 +00:00
matt335672 d56408a891 authentication: Replace display number with string
The display number is a concept which won't exist for Wayland displays.
We use a display nuimber instead.
2026-03-04 14:32:21 +00:00
matt335672 656a125cc0 utmp: Remove display number from interface
The display number will not be a valid concept for Wayland, so the
display number parameter is replaced with a display string.
2026-03-04 14:32:21 +00:00
matt335672 fd43cd5d85 CI: Prevent some format truncation errors 2026-03-04 14:32:21 +00:00