Denis Skvortsov
b824c93b86
Fix for DYNVC Multi-Chunk Reassembly Logic Defects
2026-07-15 17:24:30 +03:00
metalefty
bb0c5984c2
Merge commit from fork
...
CVE-2026-54538: Pre-auth infinite loop in TS_SHARECONTROLHEADER
2026-07-02 17:30:17 +09:00
metalefty
2c2eff3b59
Merge commit from fork
...
CVE-2026-55639: OOB read in GCC Conference Create Request
2026-07-02 17:09:54 +09:00
metalefty
0aae834802
Merge commit from fork
...
CVE-2026-55645: OOB read in Client Control PDU processing
2026-07-02 16:57:51 +09:00
metalefty
0af3b1ecf8
Merge commit from fork
...
CVE-2026-44978: Check FIPS PDU padding value before use
2026-07-01 17:56:20 +09:00
metalefty
b3e1a5f17d
Merge commit from fork
...
CVE-2026-55238: Possible OOB reads in capability processing
2026-07-01 17:45:49 +09:00
matt335672
4aa8bdf1ea
CVE-2026-55238: Possible OOB reads in capability processing
...
Add missing per-capability length checks in the RDP Confirm Active PDU
parser, and abort the parser if a buffer length violation is discovered.
2026-06-17 09:22:05 +01:00
matt335672
9d16ec4e75
CVE-2026-55639: OOB read in GCC Conference Create Request
2026-06-17 09:18:20 +01:00
matt335672
b1edb60c1d
CVE-2026-55645: OOB read in Client Control PDU processing
2026-06-17 09:14:18 +01:00
matt335672
2394084bf4
CVE-2026-54538: Pre-auth infinite loop in TS_SHARECONTROLHEADER
2026-06-16 09:50:01 +01:00
Leonard Nielsen
40c1a316f4
Allow for token logon even with INFO_AUTOLOGON flag set
2026-06-11 14:40:59 +02:00
matt335672
e42951868b
CVE-2026-44978: Check FIPS PDU padding value before use
2026-05-11 10:46:50 +01:00
matt335672
5fa4dc02bc
regression: Fix SEGV in xrdp when running over TLS
...
When not using classic RDP encryption, an uninitialsed pointer can be
passed to sig64_to_uint64() in development mode.
2026-04-20 13:34:09 +01:00
metalefty
41f6e6b995
Merge pull request #3782 from metalefty/cifix
...
Supress -Wunused-function warnings
2026-04-16 07:34:23 +09:00
Koichiro Iwao
5e7a7c046d
Supress -Wunused-function warnings
...
`sig64_to_uint64()` is only called when devel logging is enabled.
Guard the function with USE_DEVEL_LOGGING macro.
2026-04-15 21:13:29 +09:00
metalefty
7738d111d5
Merge commit from fork
...
CVE-2026-35512: Heap overflow in dynvc processing
2026-04-14 17:00:20 +09:00
metalefty
6d1f89a919
Merge commit from fork
...
CVE-2026-33516 : Address potential OOB read
2026-04-14 15:01:23 +09:00
metalefty
1bacf22fb7
Merge commit from fork
...
Check HMAC values when non-TLS connections are used
2026-04-14 14:06:45 +09:00
metalefty
220a50b1d2
Merge commit from fork
...
CVE-2026-32624: buffer overflow if domain sep used
2026-04-14 09:30:27 +09:00
matt335672
41a4af0a36
CVE-2026-35512: Heap overflow in dynvc processing
...
Length checking for the EGFX dynamic virtual channel is inadequate,
allowing for heap overflows to be forced by a malicious client before
authentication.
2026-04-06 12:39:32 +01:00
matt335672
6831249bed
CVE-2026-33516 : Address potential OOB read
...
The codec list processing code contains a potential out-of-bounds
read, as the length check comes after the data is read.
2026-04-02 11:23:42 +01:00
gpotter2
42b830f124
Rename RDP_INFO flags to spec names, add missing
2026-03-31 21:22:33 +02:00
matt335672
f1a2bec415
CVE-2026-32624: buffer overflow if domain sep used
...
Check the username buffer is not overflowed if the domain separator
feature is used.
2026-03-13 17:08:14 +00:00
matt335672
03b5d2cccb
Code quality: Improve HMAC logging for security
...
The development logging for HMAC values is poor. Add a function to
make this a lot clearer.
2026-03-11 15:58:56 +00:00
matt335672
187d22cef8
security: Check HMAC on non-FIPS fastpath input
...
CVE-2026-32105: Add a check that the HMAC signature supplied with a
non-FIPS fastpath input PDU matches the calculated signature.
2026-03-11 15:58:41 +00:00
matt335672
759104912c
security: Check HMAC on non-FIPS slowpath input
...
CVE-2026-32105: Add a check that the HMAC signature supplied with a
non-FIPS slowpath input PDU matches the calculated signature.
2026-03-11 15:58:19 +00:00
matt335672
0d8cf57e9d
security: Check HMAC on FIPS slowpath input
...
CVE-2026-32105: Add a check that the HMAC signature supplied with a
FIPS slowpath input PDU matches the calculated signature.
2026-03-11 15:57:57 +00:00
matt335672
2a411f7525
security: Check HMAC on FIPS fastpath input
...
CVE-2026-32105: Add a check that the HMAC signature supplied with a
FIPS fastpath input PDU matches the calculated signature.
2026-03-11 15:56:55 +00:00
firewave
214cf50df5
fixed some unreadVariable Cppcheck warnings
2026-03-03 16:33:51 +01:00
Jay Sorg
5637721f5a
add move_cursor
2026-01-30 18:54:57 -08:00
matt335672
4b87cfc08f
Merge pull request #2831 from firewave/wdoc
...
mitigated `-Wdocumentation` and `-Wdocumentation-unknown-command` Clang compiler warnings
2025-11-06 11:21:40 +00:00
firewave
d580c8d339
adjusted some includes
2025-11-04 13:41:26 +01:00
firewave
67c11f0443
mitigated -Wdocumentation and -Wdocumentation-unknown-command Clang compiler warnings
2025-11-04 13:40:33 +01:00
matt335672
c646002779
Code quality: Remove 'struct xrdp_process *' casts
...
The first argument to libxrdp_init() is a intptr_t / tbus value. This
represents the xrdp instance which is using the library, but this value
is always a 'struct xrdp_process' pointer.
This PR replaces the intptr_t with an incomplete type declaration at
the interface between xrdp and libxrdp.
The original intention was probably to provide some separation from
xrdp and the libxrdp code, but in practice this has turned out not to be
useful.
2025-11-03 10:34:42 +00:00
matt335672
bafd7eb2df
login screen: Use fastpath updates if available
...
If output fastpath is enabled, use TS_FP_UPDATE_BITMAP rather than
TS_UPDATE_BITMAP for the login screen.
2025-10-27 10:47:19 +00:00
matt335672
7f6899567b
Allow TLS pre-master secrets to be recorded
...
This allows for RDP sessions to be easily decrypted within Wireshark
2025-09-12 11:55:19 +01:00
matt335672
127a95e254
struct xrdp_session: Remove void * pointers
...
void * pointers in xrdp_session are replaced with pointers to
incomplete types. This allows us to remove a very large number of casts
related to these members in libxrdp.c
2025-09-09 15:16:32 +01:00
matt335672
0a13316e6a
ms-rdpbcgr.h: Rename incorrect slow path constants
...
Rename the defines from [MS-RDPBCGR] 2.2.9.1.1.3.1 to match
the documentation.
2025-09-09 15:15:46 +01:00
matt335672
2759680b8b
ms-rdpbcgr.h: Rename incorrect PDUTYPE2_ defines
...
Rename the defines from [MS-RDPBCGR] 2.2.8.1.1.1.2 to
match the documentation.
2025-09-09 15:14:28 +01:00
matt335672
557b580cb0
ms-rdpbcgr.h : Rename incorrect pointer update constants
...
Rename the defines from [MS-RDPBCGR] 2.2.9.1.1.4 and
2.2.9.1.1.4.3 to match the documentation.
2025-09-09 15:11:45 +01:00
matt335672
aade869fb7
Merge pull request #3607 from matt335672/fix_incorrect_control_pdu_vals
...
Fix more inconsistencies with [MS-RDPBCGR]
2025-09-06 10:04:35 +01:00
matt335672
fa6ed3c702
Fix more inconsistencies with [MS-RDPBCGR]
2025-09-05 12:19:56 +01:00
matt335672
4c8f2abf6d
Fill in all fields for TS_DEACTIVATE_ALL_PDU
2025-09-05 11:42:44 +01:00
matt335672
ac95cdffc3
Rename client_info hostname to client_name
...
This name better matches the name from [MS-RDPBCGR]. Also, the size
of the UTF-8 buffer allocated for the client name is not large
enough for some of the names which could potentially be passed across
in UTF-16 from the client.
2025-07-21 11:30:14 +01:00
matt335672
d015535065
Add CCP support to xrdp
...
This allows sesexec to send a reason for a connection close
request to xrdp.
xrdp is also updated to support server initiated disconnection sequences
from [MS-RDPBCGR] 1.3.1.4, along with reporting a reason to the client
for the disconnection.
2025-07-21 11:30:14 +01:00
matt335672
b2892fbe5e
Factor out xup_client_info for xorgxrdp
...
The data in 'struct xrdp_client_info' which is shared with xorgxrdp
is separated out into a separate structure. This makes it simpler to
change 'struct xrdp_client_info' without affecting xorgxrdp.
2025-05-28 11:53:21 +01:00
matt335672
6ba1503b6a
Disable vmconnect mode for non-vsock connections
2025-05-08 11:51:32 +01:00
gpotter2
09e1173259
Apply suggestions
...
Co-Authored-By: matt335672 <30179339+matt335672@users.noreply.github.com >
2025-05-08 06:45:05 +02:00
gpotter2
f0bae0050c
vmconnect mode: support all security modes when used in Hyper-V environment
2025-05-06 21:49:56 +02:00
matt335672
463e500f77
Security improvements
...
1) In FIPS mode, Classic RDP security is not allowed at all.
2) In FIPS mode xrdp-keygen creates an empty file
3) Documentation wording improved around the security_level setting
4) Logging improved around the security negotiation
5) Warnings now generated if Classic RDP security is negotiated
2025-05-06 11:30:36 +01:00