Commit Graph

597 Commits

Author SHA1 Message Date
metalefty b3e1a5f17d Merge commit from fork
CVE-2026-55238: Possible OOB reads in capability processing
2026-07-01 17:45:49 +09:00
matt335672 4aa8bdf1ea CVE-2026-55238: Possible OOB reads in capability processing
Add missing per-capability length checks in the RDP Confirm Active PDU
parser, and abort the parser if a buffer length violation is discovered.
2026-06-17 09:22:05 +01:00
Leonard Nielsen 40c1a316f4 Allow for token logon even with INFO_AUTOLOGON flag set 2026-06-11 14:40:59 +02:00
matt335672 5fa4dc02bc regression: Fix SEGV in xrdp when running over TLS
When not using classic RDP encryption, an uninitialsed pointer can be
passed to sig64_to_uint64() in development mode.
2026-04-20 13:34:09 +01:00
metalefty 41f6e6b995 Merge pull request #3782 from metalefty/cifix
Supress -Wunused-function warnings
2026-04-16 07:34:23 +09:00
Koichiro Iwao 5e7a7c046d Supress -Wunused-function warnings
`sig64_to_uint64()` is only called when devel logging is enabled.
Guard the function with USE_DEVEL_LOGGING macro.
2026-04-15 21:13:29 +09:00
metalefty 7738d111d5 Merge commit from fork
CVE-2026-35512: Heap overflow in dynvc processing
2026-04-14 17:00:20 +09:00
metalefty 6d1f89a919 Merge commit from fork
CVE-2026-33516 : Address potential OOB read
2026-04-14 15:01:23 +09:00
metalefty 1bacf22fb7 Merge commit from fork
Check HMAC values when non-TLS connections are used
2026-04-14 14:06:45 +09:00
metalefty 220a50b1d2 Merge commit from fork
CVE-2026-32624: buffer overflow if domain sep used
2026-04-14 09:30:27 +09:00
matt335672 41a4af0a36 CVE-2026-35512: Heap overflow in dynvc processing
Length checking for the EGFX dynamic virtual channel is inadequate,
allowing for heap overflows to be forced by a malicious client before
authentication.
2026-04-06 12:39:32 +01:00
matt335672 6831249bed CVE-2026-33516 : Address potential OOB read
The codec list processing code contains a potential out-of-bounds
read, as the length check comes after the data is read.
2026-04-02 11:23:42 +01:00
gpotter2 42b830f124 Rename RDP_INFO flags to spec names, add missing 2026-03-31 21:22:33 +02:00
matt335672 f1a2bec415 CVE-2026-32624: buffer overflow if domain sep used
Check the username buffer is not overflowed if the domain separator
feature is used.
2026-03-13 17:08:14 +00:00
matt335672 03b5d2cccb Code quality: Improve HMAC logging for security
The development logging for HMAC values is poor. Add a function to
make this a lot clearer.
2026-03-11 15:58:56 +00:00
matt335672 187d22cef8 security: Check HMAC on non-FIPS fastpath input
CVE-2026-32105: Add a check that the HMAC signature supplied with a
non-FIPS fastpath input PDU matches the calculated signature.
2026-03-11 15:58:41 +00:00
matt335672 759104912c security: Check HMAC on non-FIPS slowpath input
CVE-2026-32105: Add a check that the HMAC signature supplied with a
non-FIPS slowpath input PDU matches the calculated signature.
2026-03-11 15:58:19 +00:00
matt335672 0d8cf57e9d security: Check HMAC on FIPS slowpath input
CVE-2026-32105: Add a check that the HMAC signature supplied with a
FIPS slowpath input PDU matches the calculated signature.
2026-03-11 15:57:57 +00:00
matt335672 2a411f7525 security: Check HMAC on FIPS fastpath input
CVE-2026-32105: Add a check that the HMAC signature supplied with a
FIPS fastpath input PDU matches the calculated signature.
2026-03-11 15:56:55 +00:00
firewave 214cf50df5 fixed some unreadVariable Cppcheck warnings 2026-03-03 16:33:51 +01:00
Jay Sorg 5637721f5a add move_cursor 2026-01-30 18:54:57 -08:00
matt335672 4b87cfc08f Merge pull request #2831 from firewave/wdoc
mitigated `-Wdocumentation` and `-Wdocumentation-unknown-command` Clang compiler warnings
2025-11-06 11:21:40 +00:00
firewave d580c8d339 adjusted some includes 2025-11-04 13:41:26 +01:00
firewave 67c11f0443 mitigated -Wdocumentation and -Wdocumentation-unknown-command Clang compiler warnings 2025-11-04 13:40:33 +01:00
matt335672 c646002779 Code quality: Remove 'struct xrdp_process *' casts
The first argument to libxrdp_init() is a intptr_t / tbus value. This
represents the xrdp instance which is using the library, but this value
is always a 'struct xrdp_process' pointer.

This PR replaces the intptr_t with an incomplete type declaration at
the interface between xrdp and libxrdp.

The original intention was probably to provide some separation from
xrdp and the libxrdp code, but in practice this has turned out not to be
useful.
2025-11-03 10:34:42 +00:00
matt335672 bafd7eb2df login screen: Use fastpath updates if available
If output fastpath is enabled, use TS_FP_UPDATE_BITMAP rather than
TS_UPDATE_BITMAP for the login screen.
2025-10-27 10:47:19 +00:00
matt335672 7f6899567b Allow TLS pre-master secrets to be recorded
This allows for RDP sessions to be easily decrypted within Wireshark
2025-09-12 11:55:19 +01:00
matt335672 127a95e254 struct xrdp_session: Remove void * pointers
void * pointers in xrdp_session are replaced with pointers to
incomplete types. This allows us to remove a very large number of casts
related to these members in libxrdp.c
2025-09-09 15:16:32 +01:00
matt335672 0a13316e6a ms-rdpbcgr.h: Rename incorrect slow path constants
Rename the defines from [MS-RDPBCGR] 2.2.9.1.1.3.1 to match
the documentation.
2025-09-09 15:15:46 +01:00
matt335672 2759680b8b ms-rdpbcgr.h: Rename incorrect PDUTYPE2_ defines
Rename the defines from [MS-RDPBCGR] 2.2.8.1.1.1.2 to
match the documentation.
2025-09-09 15:14:28 +01:00
matt335672 557b580cb0 ms-rdpbcgr.h : Rename incorrect pointer update constants
Rename the defines from [MS-RDPBCGR] 2.2.9.1.1.4 and
2.2.9.1.1.4.3 to match the documentation.
2025-09-09 15:11:45 +01:00
matt335672 aade869fb7 Merge pull request #3607 from matt335672/fix_incorrect_control_pdu_vals
Fix more inconsistencies with [MS-RDPBCGR]
2025-09-06 10:04:35 +01:00
matt335672 fa6ed3c702 Fix more inconsistencies with [MS-RDPBCGR] 2025-09-05 12:19:56 +01:00
matt335672 4c8f2abf6d Fill in all fields for TS_DEACTIVATE_ALL_PDU 2025-09-05 11:42:44 +01:00
matt335672 ac95cdffc3 Rename client_info hostname to client_name
This name better matches the name from [MS-RDPBCGR]. Also, the size
of the UTF-8 buffer allocated for the client name is not large
enough for some of the names which could potentially be passed across
in UTF-16 from the client.
2025-07-21 11:30:14 +01:00
matt335672 d015535065 Add CCP support to xrdp
This allows sesexec to send a reason for a connection close
request to xrdp.

xrdp is also updated to support server initiated disconnection sequences
from [MS-RDPBCGR] 1.3.1.4, along with reporting a reason to the client
for the disconnection.
2025-07-21 11:30:14 +01:00
matt335672 b2892fbe5e Factor out xup_client_info for xorgxrdp
The data in 'struct xrdp_client_info' which is shared with xorgxrdp
is separated out into a separate structure. This makes it simpler to
change 'struct xrdp_client_info' without affecting xorgxrdp.
2025-05-28 11:53:21 +01:00
matt335672 6ba1503b6a Disable vmconnect mode for non-vsock connections 2025-05-08 11:51:32 +01:00
gpotter2 09e1173259 Apply suggestions
Co-Authored-By: matt335672 <30179339+matt335672@users.noreply.github.com>
2025-05-08 06:45:05 +02:00
gpotter2 f0bae0050c vmconnect mode: support all security modes when used in Hyper-V environment 2025-05-06 21:49:56 +02:00
matt335672 463e500f77 Security improvements
1) In FIPS mode, Classic RDP security is not allowed at all.
2) In FIPS mode xrdp-keygen creates an empty file
3) Documentation wording improved around the security_level setting
4) Logging improved around the security negotiation
5) Warnings now generated if Classic RDP security is negotiated
2025-05-06 11:30:36 +01:00
matt335672 554515e39c Refactor static channel name handling
1) Remove 'magic numbers' related to static channel name lengths, and
   replace with CHANNEL_NAME_LEN, or CHANNEL_NAME_LEN+1, as appropriate.
2) Always add static channel definitions, even if they are malformed.
3) Log channels which the client sends, which aren't named in
   the [Channels] section of xrdp.ini.

(cherry picked from commit 9092d898b7dceda713bd05b296ea8e8213ee614b)
2025-04-26 17:06:10 +01:00
matt335672 ffe9ac9122 Coverity CID 468130
g_bitmask_to_str() can return < 0 on error. This is not adequately
catered for.
2025-04-22 14:51:26 +01:00
Jay Sorg 522b5750d9 add system pointer 2025-03-21 23:04:15 -07:00
Koichiro Iwao 75736f4853 Allow to change config file (sub)directory
This allows the `xrdp` part of the path `/etc/xrdp` where config files
are placed to be customizable. This change is useful when trying the
stable version and the devel version alternately.
2024-12-27 10:53:31 +09:00
matt335672 28ad8c6ee1 Merge pull request #3261 from matt335672/skip_channeljoin
Improve channel join request processing
2024-10-21 16:00:04 +01:00
matt335672 10cf8f2d1c Remove xrdp_sec_in_mcs_data() function
THe function xrdp_sec_in_mcs_data() parses data within the
TS_UD_CS_CORE struct which could just as easily be parsed
when xrdp_sec_process_mcs_data_CS_CORE() is called.

Currently the contents of the MSC Connect Initial PDU are stored within
the client_mcs_data member of the xrdp_sec struct. This stream is parsed
once by xrdp_sec_process_mcs_data() and then separately by
xrdp_sec_in_mcs_data(). There is no reason not to perform the parse in
a single pass through the stream.

This commit folds the functionality in xrdp_sec_in_mcs_data() into
xrdp_sec_process_mcs_data_CS_CORE() and removes xrdp_sec_in_mcs_data()
2024-09-30 14:59:43 +01:00
matt335672 f4d73054a9 Use client earlyCapabilities to determine channel join count
We always now indicate we support skipping channel joins. If the client
indicates this too, expect no channel join requests from the client.

If we do get some, process them anyway.
2024-09-29 14:51:38 +01:00
matt335672 fcc82c3499 Announce server RNS_UD_SC_SKIP_CHANNELJOIN_SUPPORTED 2024-09-29 14:20:48 +01:00
matt335672 7eb586d1ae Combine code paths for handling channel joins
The existing code contains separate TLS and non-TLS code paths for
hadling channel join PDUs. This was introduced in
8fdc1ba216 and was based on a
misunderstanding of where in the connection sequence the TLS client hello
is processed (if a TLS connection is negotiated). The assumption was
the TLS client hello is received after the channel join PDUs. However,
it is actually received immediately after the X.224 Connection Confirm
PDU some time before channel join requests are processed.

Consequently, there is no reason not to adopt a single code path for
handling channel joins.
2024-09-29 14:11:02 +01:00