Commit Graph

606 Commits

Author SHA1 Message Date
Denis Skvortsov b824c93b86 Fix for DYNVC Multi-Chunk Reassembly Logic Defects 2026-07-15 17:24:30 +03:00
metalefty bb0c5984c2 Merge commit from fork
CVE-2026-54538: Pre-auth infinite loop in TS_SHARECONTROLHEADER
2026-07-02 17:30:17 +09:00
metalefty 2c2eff3b59 Merge commit from fork
CVE-2026-55639: OOB read in GCC Conference Create Request
2026-07-02 17:09:54 +09:00
metalefty 0aae834802 Merge commit from fork
CVE-2026-55645: OOB read in Client Control PDU processing
2026-07-02 16:57:51 +09:00
metalefty 0af3b1ecf8 Merge commit from fork
CVE-2026-44978: Check FIPS PDU padding value before use
2026-07-01 17:56:20 +09:00
metalefty b3e1a5f17d Merge commit from fork
CVE-2026-55238: Possible OOB reads in capability processing
2026-07-01 17:45:49 +09:00
matt335672 4aa8bdf1ea CVE-2026-55238: Possible OOB reads in capability processing
Add missing per-capability length checks in the RDP Confirm Active PDU
parser, and abort the parser if a buffer length violation is discovered.
2026-06-17 09:22:05 +01:00
matt335672 9d16ec4e75 CVE-2026-55639: OOB read in GCC Conference Create Request 2026-06-17 09:18:20 +01:00
matt335672 b1edb60c1d CVE-2026-55645: OOB read in Client Control PDU processing 2026-06-17 09:14:18 +01:00
matt335672 2394084bf4 CVE-2026-54538: Pre-auth infinite loop in TS_SHARECONTROLHEADER 2026-06-16 09:50:01 +01:00
Leonard Nielsen 40c1a316f4 Allow for token logon even with INFO_AUTOLOGON flag set 2026-06-11 14:40:59 +02:00
matt335672 e42951868b CVE-2026-44978: Check FIPS PDU padding value before use 2026-05-11 10:46:50 +01:00
matt335672 5fa4dc02bc regression: Fix SEGV in xrdp when running over TLS
When not using classic RDP encryption, an uninitialsed pointer can be
passed to sig64_to_uint64() in development mode.
2026-04-20 13:34:09 +01:00
metalefty 41f6e6b995 Merge pull request #3782 from metalefty/cifix
Supress -Wunused-function warnings
2026-04-16 07:34:23 +09:00
Koichiro Iwao 5e7a7c046d Supress -Wunused-function warnings
`sig64_to_uint64()` is only called when devel logging is enabled.
Guard the function with USE_DEVEL_LOGGING macro.
2026-04-15 21:13:29 +09:00
metalefty 7738d111d5 Merge commit from fork
CVE-2026-35512: Heap overflow in dynvc processing
2026-04-14 17:00:20 +09:00
metalefty 6d1f89a919 Merge commit from fork
CVE-2026-33516 : Address potential OOB read
2026-04-14 15:01:23 +09:00
metalefty 1bacf22fb7 Merge commit from fork
Check HMAC values when non-TLS connections are used
2026-04-14 14:06:45 +09:00
metalefty 220a50b1d2 Merge commit from fork
CVE-2026-32624: buffer overflow if domain sep used
2026-04-14 09:30:27 +09:00
matt335672 41a4af0a36 CVE-2026-35512: Heap overflow in dynvc processing
Length checking for the EGFX dynamic virtual channel is inadequate,
allowing for heap overflows to be forced by a malicious client before
authentication.
2026-04-06 12:39:32 +01:00
matt335672 6831249bed CVE-2026-33516 : Address potential OOB read
The codec list processing code contains a potential out-of-bounds
read, as the length check comes after the data is read.
2026-04-02 11:23:42 +01:00
gpotter2 42b830f124 Rename RDP_INFO flags to spec names, add missing 2026-03-31 21:22:33 +02:00
matt335672 f1a2bec415 CVE-2026-32624: buffer overflow if domain sep used
Check the username buffer is not overflowed if the domain separator
feature is used.
2026-03-13 17:08:14 +00:00
matt335672 03b5d2cccb Code quality: Improve HMAC logging for security
The development logging for HMAC values is poor. Add a function to
make this a lot clearer.
2026-03-11 15:58:56 +00:00
matt335672 187d22cef8 security: Check HMAC on non-FIPS fastpath input
CVE-2026-32105: Add a check that the HMAC signature supplied with a
non-FIPS fastpath input PDU matches the calculated signature.
2026-03-11 15:58:41 +00:00
matt335672 759104912c security: Check HMAC on non-FIPS slowpath input
CVE-2026-32105: Add a check that the HMAC signature supplied with a
non-FIPS slowpath input PDU matches the calculated signature.
2026-03-11 15:58:19 +00:00
matt335672 0d8cf57e9d security: Check HMAC on FIPS slowpath input
CVE-2026-32105: Add a check that the HMAC signature supplied with a
FIPS slowpath input PDU matches the calculated signature.
2026-03-11 15:57:57 +00:00
matt335672 2a411f7525 security: Check HMAC on FIPS fastpath input
CVE-2026-32105: Add a check that the HMAC signature supplied with a
FIPS fastpath input PDU matches the calculated signature.
2026-03-11 15:56:55 +00:00
firewave 214cf50df5 fixed some unreadVariable Cppcheck warnings 2026-03-03 16:33:51 +01:00
Jay Sorg 5637721f5a add move_cursor 2026-01-30 18:54:57 -08:00
matt335672 4b87cfc08f Merge pull request #2831 from firewave/wdoc
mitigated `-Wdocumentation` and `-Wdocumentation-unknown-command` Clang compiler warnings
2025-11-06 11:21:40 +00:00
firewave d580c8d339 adjusted some includes 2025-11-04 13:41:26 +01:00
firewave 67c11f0443 mitigated -Wdocumentation and -Wdocumentation-unknown-command Clang compiler warnings 2025-11-04 13:40:33 +01:00
matt335672 c646002779 Code quality: Remove 'struct xrdp_process *' casts
The first argument to libxrdp_init() is a intptr_t / tbus value. This
represents the xrdp instance which is using the library, but this value
is always a 'struct xrdp_process' pointer.

This PR replaces the intptr_t with an incomplete type declaration at
the interface between xrdp and libxrdp.

The original intention was probably to provide some separation from
xrdp and the libxrdp code, but in practice this has turned out not to be
useful.
2025-11-03 10:34:42 +00:00
matt335672 bafd7eb2df login screen: Use fastpath updates if available
If output fastpath is enabled, use TS_FP_UPDATE_BITMAP rather than
TS_UPDATE_BITMAP for the login screen.
2025-10-27 10:47:19 +00:00
matt335672 7f6899567b Allow TLS pre-master secrets to be recorded
This allows for RDP sessions to be easily decrypted within Wireshark
2025-09-12 11:55:19 +01:00
matt335672 127a95e254 struct xrdp_session: Remove void * pointers
void * pointers in xrdp_session are replaced with pointers to
incomplete types. This allows us to remove a very large number of casts
related to these members in libxrdp.c
2025-09-09 15:16:32 +01:00
matt335672 0a13316e6a ms-rdpbcgr.h: Rename incorrect slow path constants
Rename the defines from [MS-RDPBCGR] 2.2.9.1.1.3.1 to match
the documentation.
2025-09-09 15:15:46 +01:00
matt335672 2759680b8b ms-rdpbcgr.h: Rename incorrect PDUTYPE2_ defines
Rename the defines from [MS-RDPBCGR] 2.2.8.1.1.1.2 to
match the documentation.
2025-09-09 15:14:28 +01:00
matt335672 557b580cb0 ms-rdpbcgr.h : Rename incorrect pointer update constants
Rename the defines from [MS-RDPBCGR] 2.2.9.1.1.4 and
2.2.9.1.1.4.3 to match the documentation.
2025-09-09 15:11:45 +01:00
matt335672 aade869fb7 Merge pull request #3607 from matt335672/fix_incorrect_control_pdu_vals
Fix more inconsistencies with [MS-RDPBCGR]
2025-09-06 10:04:35 +01:00
matt335672 fa6ed3c702 Fix more inconsistencies with [MS-RDPBCGR] 2025-09-05 12:19:56 +01:00
matt335672 4c8f2abf6d Fill in all fields for TS_DEACTIVATE_ALL_PDU 2025-09-05 11:42:44 +01:00
matt335672 ac95cdffc3 Rename client_info hostname to client_name
This name better matches the name from [MS-RDPBCGR]. Also, the size
of the UTF-8 buffer allocated for the client name is not large
enough for some of the names which could potentially be passed across
in UTF-16 from the client.
2025-07-21 11:30:14 +01:00
matt335672 d015535065 Add CCP support to xrdp
This allows sesexec to send a reason for a connection close
request to xrdp.

xrdp is also updated to support server initiated disconnection sequences
from [MS-RDPBCGR] 1.3.1.4, along with reporting a reason to the client
for the disconnection.
2025-07-21 11:30:14 +01:00
matt335672 b2892fbe5e Factor out xup_client_info for xorgxrdp
The data in 'struct xrdp_client_info' which is shared with xorgxrdp
is separated out into a separate structure. This makes it simpler to
change 'struct xrdp_client_info' without affecting xorgxrdp.
2025-05-28 11:53:21 +01:00
matt335672 6ba1503b6a Disable vmconnect mode for non-vsock connections 2025-05-08 11:51:32 +01:00
gpotter2 09e1173259 Apply suggestions
Co-Authored-By: matt335672 <30179339+matt335672@users.noreply.github.com>
2025-05-08 06:45:05 +02:00
gpotter2 f0bae0050c vmconnect mode: support all security modes when used in Hyper-V environment 2025-05-06 21:49:56 +02:00
matt335672 463e500f77 Security improvements
1) In FIPS mode, Classic RDP security is not allowed at all.
2) In FIPS mode xrdp-keygen creates an empty file
3) Documentation wording improved around the security_level setting
4) Logging improved around the security negotiation
5) Warnings now generated if Classic RDP security is negotiated
2025-05-06 11:30:36 +01:00