matt335672
63afb676e6
drdynvc: Improve dynamic channel support
...
The dynamic channel handler in xrdp_channel.c is updated to allow
the procs `data_first` pointer to be NULL. If this is done, the
channel handler performs all the dechunking necessary for the channel,
and only complete data PDUs are passed to procs 'data' callback.
This facility is applied to the dynamic channels supported by xrdp_mm.c.
The incoming callbacks for these channels now provide complete support
for the specification in [MS-RDPEDYC]. The existing channels were
incomplete in these respects:
1) The "Microsoft::Windows::RDS::Graphics" channel handler did not
support incoming PDUs between 1591 and 1600 bytes. The specification
calls for these to be sent as a single DATA_FIRST PDU.
2) The "Microsoft::Windows::RDS::DisplayControl" channel handler did
not support incoming PDUs over 1590 bytes.
2026-08-12 11:31:47 +01:00
matt335672
f745c9152d
drdynvc: Change channel processing to use streams
...
The channel processor in xrdp_channel.c for dynamic streams uses
a data pointer and a length for passing PDUs or PDU fragments. We
replace this with a standard stream pointer, so that the usual
facilities can be used for checking length violcations.
2026-08-12 11:31:47 +01:00
matt335672
fe850a22c0
Merge pull request #3839 from matt335672/add_dechunker
...
Add dechunker module
2026-07-28 10:46:27 +01:00
matt335672
3d137431a9
Merge pull request #3837 from the-deniss/fix/trans_force_read_s-bounds-check-uses-wrong-pointer
...
Fix for trans_force_read_s Bounds Check Uses Wrong Pointer
2026-07-28 10:10:45 +01:00
Denis Skvortsov
b36ad7b2d0
Cast to size_t in bounds macros; drop resulting dead check
2026-07-27 15:35:26 +03:00
matt335672
be95ba3017
dechunker: Create separate module for dechunking
...
The code in xrdp_channel.c to handle dechunking on a virtual channel is
moved to a separate module to allow for better sharing of logic.
2026-07-23 19:20:28 +01:00
matt335672
c73c827e5a
compilation: Fix errors
...
Fix compilation issues with b824c93b86
2026-07-16 10:41:40 +01:00
Denis Skvortsov
b824c93b86
Fix for DYNVC Multi-Chunk Reassembly Logic Defects
2026-07-15 17:24:30 +03:00
metalefty
bb0c5984c2
Merge commit from fork
...
CVE-2026-54538: Pre-auth infinite loop in TS_SHARECONTROLHEADER
2026-07-02 17:30:17 +09:00
metalefty
2c2eff3b59
Merge commit from fork
...
CVE-2026-55639: OOB read in GCC Conference Create Request
2026-07-02 17:09:54 +09:00
metalefty
0aae834802
Merge commit from fork
...
CVE-2026-55645: OOB read in Client Control PDU processing
2026-07-02 16:57:51 +09:00
metalefty
0af3b1ecf8
Merge commit from fork
...
CVE-2026-44978: Check FIPS PDU padding value before use
2026-07-01 17:56:20 +09:00
metalefty
b3e1a5f17d
Merge commit from fork
...
CVE-2026-55238: Possible OOB reads in capability processing
2026-07-01 17:45:49 +09:00
matt335672
4aa8bdf1ea
CVE-2026-55238: Possible OOB reads in capability processing
...
Add missing per-capability length checks in the RDP Confirm Active PDU
parser, and abort the parser if a buffer length violation is discovered.
2026-06-17 09:22:05 +01:00
matt335672
9d16ec4e75
CVE-2026-55639: OOB read in GCC Conference Create Request
2026-06-17 09:18:20 +01:00
matt335672
b1edb60c1d
CVE-2026-55645: OOB read in Client Control PDU processing
2026-06-17 09:14:18 +01:00
matt335672
2394084bf4
CVE-2026-54538: Pre-auth infinite loop in TS_SHARECONTROLHEADER
2026-06-16 09:50:01 +01:00
Leonard Nielsen
40c1a316f4
Allow for token logon even with INFO_AUTOLOGON flag set
2026-06-11 14:40:59 +02:00
matt335672
e42951868b
CVE-2026-44978: Check FIPS PDU padding value before use
2026-05-11 10:46:50 +01:00
matt335672
5fa4dc02bc
regression: Fix SEGV in xrdp when running over TLS
...
When not using classic RDP encryption, an uninitialsed pointer can be
passed to sig64_to_uint64() in development mode.
2026-04-20 13:34:09 +01:00
metalefty
41f6e6b995
Merge pull request #3782 from metalefty/cifix
...
Supress -Wunused-function warnings
2026-04-16 07:34:23 +09:00
Koichiro Iwao
5e7a7c046d
Supress -Wunused-function warnings
...
`sig64_to_uint64()` is only called when devel logging is enabled.
Guard the function with USE_DEVEL_LOGGING macro.
2026-04-15 21:13:29 +09:00
metalefty
7738d111d5
Merge commit from fork
...
CVE-2026-35512: Heap overflow in dynvc processing
2026-04-14 17:00:20 +09:00
metalefty
6d1f89a919
Merge commit from fork
...
CVE-2026-33516 : Address potential OOB read
2026-04-14 15:01:23 +09:00
metalefty
1bacf22fb7
Merge commit from fork
...
Check HMAC values when non-TLS connections are used
2026-04-14 14:06:45 +09:00
metalefty
220a50b1d2
Merge commit from fork
...
CVE-2026-32624: buffer overflow if domain sep used
2026-04-14 09:30:27 +09:00
matt335672
41a4af0a36
CVE-2026-35512: Heap overflow in dynvc processing
...
Length checking for the EGFX dynamic virtual channel is inadequate,
allowing for heap overflows to be forced by a malicious client before
authentication.
2026-04-06 12:39:32 +01:00
matt335672
6831249bed
CVE-2026-33516 : Address potential OOB read
...
The codec list processing code contains a potential out-of-bounds
read, as the length check comes after the data is read.
2026-04-02 11:23:42 +01:00
gpotter2
42b830f124
Rename RDP_INFO flags to spec names, add missing
2026-03-31 21:22:33 +02:00
matt335672
f1a2bec415
CVE-2026-32624: buffer overflow if domain sep used
...
Check the username buffer is not overflowed if the domain separator
feature is used.
2026-03-13 17:08:14 +00:00
matt335672
03b5d2cccb
Code quality: Improve HMAC logging for security
...
The development logging for HMAC values is poor. Add a function to
make this a lot clearer.
2026-03-11 15:58:56 +00:00
matt335672
187d22cef8
security: Check HMAC on non-FIPS fastpath input
...
CVE-2026-32105: Add a check that the HMAC signature supplied with a
non-FIPS fastpath input PDU matches the calculated signature.
2026-03-11 15:58:41 +00:00
matt335672
759104912c
security: Check HMAC on non-FIPS slowpath input
...
CVE-2026-32105: Add a check that the HMAC signature supplied with a
non-FIPS slowpath input PDU matches the calculated signature.
2026-03-11 15:58:19 +00:00
matt335672
0d8cf57e9d
security: Check HMAC on FIPS slowpath input
...
CVE-2026-32105: Add a check that the HMAC signature supplied with a
FIPS slowpath input PDU matches the calculated signature.
2026-03-11 15:57:57 +00:00
matt335672
2a411f7525
security: Check HMAC on FIPS fastpath input
...
CVE-2026-32105: Add a check that the HMAC signature supplied with a
FIPS fastpath input PDU matches the calculated signature.
2026-03-11 15:56:55 +00:00
firewave
214cf50df5
fixed some unreadVariable Cppcheck warnings
2026-03-03 16:33:51 +01:00
Jay Sorg
5637721f5a
add move_cursor
2026-01-30 18:54:57 -08:00
matt335672
4b87cfc08f
Merge pull request #2831 from firewave/wdoc
...
mitigated `-Wdocumentation` and `-Wdocumentation-unknown-command` Clang compiler warnings
2025-11-06 11:21:40 +00:00
firewave
d580c8d339
adjusted some includes
2025-11-04 13:41:26 +01:00
firewave
67c11f0443
mitigated -Wdocumentation and -Wdocumentation-unknown-command Clang compiler warnings
2025-11-04 13:40:33 +01:00
matt335672
c646002779
Code quality: Remove 'struct xrdp_process *' casts
...
The first argument to libxrdp_init() is a intptr_t / tbus value. This
represents the xrdp instance which is using the library, but this value
is always a 'struct xrdp_process' pointer.
This PR replaces the intptr_t with an incomplete type declaration at
the interface between xrdp and libxrdp.
The original intention was probably to provide some separation from
xrdp and the libxrdp code, but in practice this has turned out not to be
useful.
2025-11-03 10:34:42 +00:00
matt335672
bafd7eb2df
login screen: Use fastpath updates if available
...
If output fastpath is enabled, use TS_FP_UPDATE_BITMAP rather than
TS_UPDATE_BITMAP for the login screen.
2025-10-27 10:47:19 +00:00
matt335672
7f6899567b
Allow TLS pre-master secrets to be recorded
...
This allows for RDP sessions to be easily decrypted within Wireshark
2025-09-12 11:55:19 +01:00
matt335672
127a95e254
struct xrdp_session: Remove void * pointers
...
void * pointers in xrdp_session are replaced with pointers to
incomplete types. This allows us to remove a very large number of casts
related to these members in libxrdp.c
2025-09-09 15:16:32 +01:00
matt335672
0a13316e6a
ms-rdpbcgr.h: Rename incorrect slow path constants
...
Rename the defines from [MS-RDPBCGR] 2.2.9.1.1.3.1 to match
the documentation.
2025-09-09 15:15:46 +01:00
matt335672
2759680b8b
ms-rdpbcgr.h: Rename incorrect PDUTYPE2_ defines
...
Rename the defines from [MS-RDPBCGR] 2.2.8.1.1.1.2 to
match the documentation.
2025-09-09 15:14:28 +01:00
matt335672
557b580cb0
ms-rdpbcgr.h : Rename incorrect pointer update constants
...
Rename the defines from [MS-RDPBCGR] 2.2.9.1.1.4 and
2.2.9.1.1.4.3 to match the documentation.
2025-09-09 15:11:45 +01:00
matt335672
aade869fb7
Merge pull request #3607 from matt335672/fix_incorrect_control_pdu_vals
...
Fix more inconsistencies with [MS-RDPBCGR]
2025-09-06 10:04:35 +01:00
matt335672
fa6ed3c702
Fix more inconsistencies with [MS-RDPBCGR]
2025-09-05 12:19:56 +01:00
matt335672
4c8f2abf6d
Fill in all fields for TS_DEACTIVATE_ALL_PDU
2025-09-05 11:42:44 +01:00