matt335672
be95ba3017
dechunker: Create separate module for dechunking
...
The code in xrdp_channel.c to handle dechunking on a virtual channel is
moved to a separate module to allow for better sharing of logic.
2026-07-23 19:20:28 +01:00
matt335672
de284747ae
Merge pull request #3836 from matt335672/update_gfx_state_machine
...
code quality: Forward-port code review comments
2026-07-20 14:14:39 +01:00
matt335672
a5975210f0
code quality: Forward-port code comments
...
Minor change to the GFX resize state machine following
review comments on backport to v0.10:
https://github.com/neutrinolabs/xrdp/pull/3834
There are no functional changes as a result of this commit
(cherry picked from commit a2fd7b7ef7c7f7c67b429634d2a1749492198cf2)
2026-07-20 11:35:32 +01:00
matt335672
8812646d0f
Merge pull request #3829 from the-deniss/fix/dynvc-multi-chunk-reassembly-logic-defects
...
Fix for DYNVC Multi-Chunk Reassembly Logic Defects
2026-07-16 10:47:51 +01:00
matt335672
c73c827e5a
compilation: Fix errors
...
Fix compilation issues with b824c93b86
2026-07-16 10:41:40 +01:00
Denis Skvortsov
b824c93b86
Fix for DYNVC Multi-Chunk Reassembly Logic Defects
2026-07-15 17:24:30 +03:00
metalefty
3af31df3fc
Merge commit from fork
...
CVE-2026-41252: lib_palette_update Heap Buffer Overflow
2026-07-02 17:33:45 +09:00
metalefty
bb0c5984c2
Merge commit from fork
...
CVE-2026-54538: Pre-auth infinite loop in TS_SHARECONTROLHEADER
2026-07-02 17:30:17 +09:00
metalefty
5642decb5f
Merge commit from fork
...
CVE-2026-41521: lib_framebuffer_update int overflow
2026-07-02 17:24:29 +09:00
metalefty
4bf38e3d8e
Merge commit from fork
...
CVE-2026-44178: Heap overflow in xrdp->chansrv msgs
2026-07-02 17:22:04 +09:00
metalefty
2c2eff3b59
Merge commit from fork
...
CVE-2026-55639: OOB read in GCC Conference Create Request
2026-07-02 17:09:54 +09:00
metalefty
0aae834802
Merge commit from fork
...
CVE-2026-55645: OOB read in Client Control PDU processing
2026-07-02 16:57:51 +09:00
metalefty
0af3b1ecf8
Merge commit from fork
...
CVE-2026-44978: Check FIPS PDU padding value before use
2026-07-01 17:56:20 +09:00
metalefty
b3e1a5f17d
Merge commit from fork
...
CVE-2026-55238: Possible OOB reads in capability processing
2026-07-01 17:45:49 +09:00
metalefty
9627823a1b
Merge commit from fork
...
CVE-2026-55626: Disable Xvnc TCP listning in UDS mode
2026-07-01 08:51:16 +09:00
Koichiro Iwao
f76a30b577
CVE-2026-55626: Disable Xvnc TCP listning in UDS mode
2026-06-24 08:42:09 +09:00
matt335672
492bd7ed4d
Merge pull request #3813 from matt335672/update_librfxcodec
...
librfxcodec: Update to latest version in devel
2026-06-23 09:45:17 +01:00
matt335672
fea7f56280
librfxcodec: Update to latest version in devel
...
Adds these changes to the librfxcodec in devel
- 637ffa28 remove some noisy logging on startup
- 1b6c8f5a fixed constVariablePointer Cppcheck warnings
- 0f10c695 always use if-else chain for RFX_USE_ACCEL_* preprocessor checks
- 3c0d7c49 rfxencode_rgb_to_yuv.c: removed some unnecessary return values
2026-06-23 09:27:21 +01:00
matt335672
21d38d0c1e
Merge pull request #3811 from matt335672/fix_cve_2026_42218_regression
...
sesexec: Fix CVE-2026-42218 regression
2026-06-17 10:08:51 +01:00
matt335672
d4d20fc82d
sesexec: Fix CVE-2026-42218 regression
...
cppcheck has picked up on the use of an unitialised variable in
the implementation of the fix for CVE-2026-42218
2026-06-17 09:54:06 +01:00
matt335672
6cb996e355
Merge pull request #3698 from lcniel/enable_token_with_auto_logon
...
Allow username-affixed token to be used with INFO_AUTOLOGON flag set in client
2026-06-17 09:36:43 +01:00
matt335672
4aa8bdf1ea
CVE-2026-55238: Possible OOB reads in capability processing
...
Add missing per-capability length checks in the RDP Confirm Active PDU
parser, and abort the parser if a buffer length violation is discovered.
2026-06-17 09:22:05 +01:00
matt335672
9d16ec4e75
CVE-2026-55639: OOB read in GCC Conference Create Request
2026-06-17 09:18:20 +01:00
matt335672
b1edb60c1d
CVE-2026-55645: OOB read in Client Control PDU processing
2026-06-17 09:14:18 +01:00
matt335672
2394084bf4
CVE-2026-54538: Pre-auth infinite loop in TS_SHARECONTROLHEADER
2026-06-16 09:50:01 +01:00
matt335672
a85e108cdf
xrdp.ini: Remove [vnc-any] as a default section
...
As it stands, this is not suitable for production environments, as
the attached CVE shows.
2026-06-15 10:12:43 +01:00
matt335672
9834a58ca6
CVE-2026-41252: lib_palette_update Heap Buffer Overflow
2026-06-15 10:12:00 +01:00
metalefty
c56a3ea202
Merge commit from fork
...
CVE-2026-42218: Ensure auth fails take a fixed time
2026-06-15 15:40:24 +09:00
Leonard Nielsen
40c1a316f4
Allow for token logon even with INFO_AUTOLOGON flag set
2026-06-11 14:40:59 +02:00
matt335672
f94ae70148
Use symbols for desktop size limits
2026-06-08 11:12:07 +01:00
matt335672
2a94fc9674
CVE-2026-41521: lib_framebuffer_update int overflow
...
An integer overflow can lead to possible heap info leak and ASLR
bypass.
2026-05-12 10:23:11 +01:00
matt335672
e42951868b
CVE-2026-44978: Check FIPS PDU padding value before use
2026-05-11 10:46:50 +01:00
matt335672
3e39be9c8e
CVE-2026-44178: Heap overflow in xrdp->chansrv msgs
...
Some xrdp -> chansrv messages allocate a fixed-size buffer which
can be overflowed by a malicious RDP client.
2026-05-06 10:32:39 +01:00
metalefty
c8cd758283
Merge pull request #3798 from metalefty/freebsd-ci
...
CI: Switch FreeBSD CI from Cirrus CI to GitHub Actions
2026-04-29 00:36:02 +09:00
Koichiro Iwao
ad6c210c2b
CI: Run FreeBSD CI via GitHub Actions
...
Resolves: #3797
2026-04-28 11:47:13 +09:00
Koichiro Iwao
e6f350ae1a
CI: Remove Cirrus CI as the service is shutting down
2026-04-28 11:45:25 +09:00
matt335672
07479384a6
CVE-2026-42218: Ensure auth fails take a fixed time
...
Implement a constant time for password-based authentication failure.
2026-04-27 10:29:12 +01:00
matt335672
102da4f42b
Merge pull request #3792 from matt335672/sig_fix
...
regression: Fix SEGV in xrdp when running over TLS
2026-04-20 13:47:22 +01:00
matt335672
5fa4dc02bc
regression: Fix SEGV in xrdp when running over TLS
...
When not using classic RDP encryption, an uninitialsed pointer can be
passed to sig64_to_uint64() in development mode.
2026-04-20 13:34:09 +01:00
matt335672
0005893a93
Merge pull request #3681 from firewave/cppcheck-performance
...
enabled cppcheck `performance` checks
2026-04-17 16:26:20 +01:00
firewave
0410abef98
enabled cppcheck performance checks
2026-04-17 15:07:58 +02:00
metalefty
f6d3d12137
Merge pull request #3787 from metalefty/security
...
Clarify handling of duplicate vulnerability reports
2026-04-17 21:53:46 +09:00
Koichiro Iwao
3610afd52b
Clarify handling of duplicate vulnerability reports
2026-04-17 21:10:26 +09:00
matt335672
43fa055ec4
Merge pull request #3786 from matt335672/remove_ulalaca
...
ulalaca: Remove for now
2026-04-17 12:46:33 +01:00
matt335672
800b5f5e7c
ulalaca: Remove for now
...
The ulalaca module for Mac is suffering from a lack of maintenance
currently, and its inclusion is holding up the introduction of some
code quality changes. This PR removes the module for now.
2026-04-17 12:23:17 +01:00
metalefty
41f6e6b995
Merge pull request #3782 from metalefty/cifix
...
Supress -Wunused-function warnings
2026-04-16 07:34:23 +09:00
Koichiro Iwao
5e7a7c046d
Supress -Wunused-function warnings
...
`sig64_to_uint64()` is only called when devel logging is enabled.
Guard the function with USE_DEVEL_LOGGING macro.
2026-04-15 21:13:29 +09:00
metalefty
c3788a374a
Merge commit from fork
...
security: Exit on failure of env_set_user()
2026-04-14 20:39:42 +09:00
matt335672
53bc57cf59
security: Exit on failure of env_set_user()
...
CVE-2026-32107. Prevent possible privilege escalation if setuid()
fails.
2026-04-14 11:52:28 +01:00
metalefty
7738d111d5
Merge commit from fork
...
CVE-2026-35512: Heap overflow in dynvc processing
2026-04-14 17:00:20 +09:00