matt335672
f4249b3ca6
chansrv: Use common dynamic dechunker
...
Addresses CVE-2026-69169
The dynamic channel processing in chansrv is updated to allow
the dechunker to be invoked automatically if the 'data_first' proc
is set to NULL. This mirrors a change made to the xrdp_channel.c.
The processor for the AUDIO_IN channel is updated to take advantage of
this, significantly simplifing the code.
2026-08-14 12:06:20 +01:00
matt335672
77d9b49432
chansrv: Use streams for dynamic channel processing
...
Change the dynamic channel processing to use streams rather than
a data pointer and a length. This mirrors an earlier commit for
xrdp.
The reason for the change is to make it easier to check for buffer
overflows using standard stream features.
2026-08-12 11:31:47 +01:00
matt335672
63afb676e6
drdynvc: Improve dynamic channel support
...
The dynamic channel handler in xrdp_channel.c is updated to allow
the procs `data_first` pointer to be NULL. If this is done, the
channel handler performs all the dechunking necessary for the channel,
and only complete data PDUs are passed to procs 'data' callback.
This facility is applied to the dynamic channels supported by xrdp_mm.c.
The incoming callbacks for these channels now provide complete support
for the specification in [MS-RDPEDYC]. The existing channels were
incomplete in these respects:
1) The "Microsoft::Windows::RDS::Graphics" channel handler did not
support incoming PDUs between 1591 and 1600 bytes. The specification
calls for these to be sent as a single DATA_FIRST PDU.
2) The "Microsoft::Windows::RDS::DisplayControl" channel handler did
not support incoming PDUs over 1590 bytes.
2026-08-12 11:31:47 +01:00
matt335672
f745c9152d
drdynvc: Change channel processing to use streams
...
The channel processor in xrdp_channel.c for dynamic streams uses
a data pointer and a length for passing PDUs or PDU fragments. We
replace this with a standard stream pointer, so that the usual
facilities can be used for checking length violcations.
2026-08-12 11:31:47 +01:00
matt335672
e4b0621229
tests: Add tests for dynamic dechunker
2026-08-12 11:19:47 +01:00
matt335672
0a986869cc
dechunker: Add handler for Dynamic channels
2026-08-11 15:02:49 +01:00
matt335672
fe850a22c0
Merge pull request #3839 from matt335672/add_dechunker
...
Add dechunker module
2026-07-28 10:46:27 +01:00
matt335672
3d137431a9
Merge pull request #3837 from the-deniss/fix/trans_force_read_s-bounds-check-uses-wrong-pointer
...
Fix for trans_force_read_s Bounds Check Uses Wrong Pointer
2026-07-28 10:10:45 +01:00
Denis Skvortsov
b36ad7b2d0
Cast to size_t in bounds macros; drop resulting dead check
2026-07-27 15:35:26 +03:00
Denis Skvortsov
e4f4364c9b
Remove check to avoid -Wtype-limits
2026-07-25 18:47:19 +03:00
Denis Skvortsov
5ae11e2a37
Harden stream bounds checks against pointer-arithmetic overflow
2026-07-25 17:46:28 +03:00
matt335672
2e8a4a82e1
test suite: Add way to run individual common tests
2026-07-23 19:20:28 +01:00
matt335672
3ef2f8830a
Dechunker: Add tests
2026-07-23 19:20:28 +01:00
matt335672
be95ba3017
dechunker: Create separate module for dechunking
...
The code in xrdp_channel.c to handle dechunking on a virtual channel is
moved to a separate module to allow for better sharing of logic.
2026-07-23 19:20:28 +01:00
Denis Skvortsov
a2d130bc5b
Fix for trans_force_read_s Bounds Check Uses Wrong Pointer
2026-07-22 12:03:58 +03:00
matt335672
de284747ae
Merge pull request #3836 from matt335672/update_gfx_state_machine
...
code quality: Forward-port code review comments
2026-07-20 14:14:39 +01:00
matt335672
a5975210f0
code quality: Forward-port code comments
...
Minor change to the GFX resize state machine following
review comments on backport to v0.10:
https://github.com/neutrinolabs/xrdp/pull/3834
There are no functional changes as a result of this commit
(cherry picked from commit a2fd7b7ef7c7f7c67b429634d2a1749492198cf2)
2026-07-20 11:35:32 +01:00
matt335672
8812646d0f
Merge pull request #3829 from the-deniss/fix/dynvc-multi-chunk-reassembly-logic-defects
...
Fix for DYNVC Multi-Chunk Reassembly Logic Defects
2026-07-16 10:47:51 +01:00
matt335672
c73c827e5a
compilation: Fix errors
...
Fix compilation issues with b824c93b86
2026-07-16 10:41:40 +01:00
Denis Skvortsov
b824c93b86
Fix for DYNVC Multi-Chunk Reassembly Logic Defects
2026-07-15 17:24:30 +03:00
metalefty
3af31df3fc
Merge commit from fork
...
CVE-2026-41252: lib_palette_update Heap Buffer Overflow
2026-07-02 17:33:45 +09:00
metalefty
bb0c5984c2
Merge commit from fork
...
CVE-2026-54538: Pre-auth infinite loop in TS_SHARECONTROLHEADER
2026-07-02 17:30:17 +09:00
metalefty
5642decb5f
Merge commit from fork
...
CVE-2026-41521: lib_framebuffer_update int overflow
2026-07-02 17:24:29 +09:00
metalefty
4bf38e3d8e
Merge commit from fork
...
CVE-2026-44178: Heap overflow in xrdp->chansrv msgs
2026-07-02 17:22:04 +09:00
metalefty
2c2eff3b59
Merge commit from fork
...
CVE-2026-55639: OOB read in GCC Conference Create Request
2026-07-02 17:09:54 +09:00
metalefty
0aae834802
Merge commit from fork
...
CVE-2026-55645: OOB read in Client Control PDU processing
2026-07-02 16:57:51 +09:00
metalefty
0af3b1ecf8
Merge commit from fork
...
CVE-2026-44978: Check FIPS PDU padding value before use
2026-07-01 17:56:20 +09:00
metalefty
b3e1a5f17d
Merge commit from fork
...
CVE-2026-55238: Possible OOB reads in capability processing
2026-07-01 17:45:49 +09:00
metalefty
9627823a1b
Merge commit from fork
...
CVE-2026-55626: Disable Xvnc TCP listning in UDS mode
2026-07-01 08:51:16 +09:00
Koichiro Iwao
f76a30b577
CVE-2026-55626: Disable Xvnc TCP listning in UDS mode
2026-06-24 08:42:09 +09:00
matt335672
492bd7ed4d
Merge pull request #3813 from matt335672/update_librfxcodec
...
librfxcodec: Update to latest version in devel
2026-06-23 09:45:17 +01:00
matt335672
fea7f56280
librfxcodec: Update to latest version in devel
...
Adds these changes to the librfxcodec in devel
- 637ffa28 remove some noisy logging on startup
- 1b6c8f5a fixed constVariablePointer Cppcheck warnings
- 0f10c695 always use if-else chain for RFX_USE_ACCEL_* preprocessor checks
- 3c0d7c49 rfxencode_rgb_to_yuv.c: removed some unnecessary return values
2026-06-23 09:27:21 +01:00
matt335672
21d38d0c1e
Merge pull request #3811 from matt335672/fix_cve_2026_42218_regression
...
sesexec: Fix CVE-2026-42218 regression
2026-06-17 10:08:51 +01:00
matt335672
d4d20fc82d
sesexec: Fix CVE-2026-42218 regression
...
cppcheck has picked up on the use of an unitialised variable in
the implementation of the fix for CVE-2026-42218
2026-06-17 09:54:06 +01:00
matt335672
6cb996e355
Merge pull request #3698 from lcniel/enable_token_with_auto_logon
...
Allow username-affixed token to be used with INFO_AUTOLOGON flag set in client
2026-06-17 09:36:43 +01:00
matt335672
4aa8bdf1ea
CVE-2026-55238: Possible OOB reads in capability processing
...
Add missing per-capability length checks in the RDP Confirm Active PDU
parser, and abort the parser if a buffer length violation is discovered.
2026-06-17 09:22:05 +01:00
matt335672
9d16ec4e75
CVE-2026-55639: OOB read in GCC Conference Create Request
2026-06-17 09:18:20 +01:00
matt335672
b1edb60c1d
CVE-2026-55645: OOB read in Client Control PDU processing
2026-06-17 09:14:18 +01:00
matt335672
2394084bf4
CVE-2026-54538: Pre-auth infinite loop in TS_SHARECONTROLHEADER
2026-06-16 09:50:01 +01:00
matt335672
a85e108cdf
xrdp.ini: Remove [vnc-any] as a default section
...
As it stands, this is not suitable for production environments, as
the attached CVE shows.
2026-06-15 10:12:43 +01:00
matt335672
9834a58ca6
CVE-2026-41252: lib_palette_update Heap Buffer Overflow
2026-06-15 10:12:00 +01:00
metalefty
c56a3ea202
Merge commit from fork
...
CVE-2026-42218: Ensure auth fails take a fixed time
2026-06-15 15:40:24 +09:00
Leonard Nielsen
40c1a316f4
Allow for token logon even with INFO_AUTOLOGON flag set
2026-06-11 14:40:59 +02:00
matt335672
f94ae70148
Use symbols for desktop size limits
2026-06-08 11:12:07 +01:00
matt335672
2a94fc9674
CVE-2026-41521: lib_framebuffer_update int overflow
...
An integer overflow can lead to possible heap info leak and ASLR
bypass.
2026-05-12 10:23:11 +01:00
matt335672
e42951868b
CVE-2026-44978: Check FIPS PDU padding value before use
2026-05-11 10:46:50 +01:00
matt335672
3e39be9c8e
CVE-2026-44178: Heap overflow in xrdp->chansrv msgs
...
Some xrdp -> chansrv messages allocate a fixed-size buffer which
can be overflowed by a malicious RDP client.
2026-05-06 10:32:39 +01:00
metalefty
c8cd758283
Merge pull request #3798 from metalefty/freebsd-ci
...
CI: Switch FreeBSD CI from Cirrus CI to GitHub Actions
2026-04-29 00:36:02 +09:00
Koichiro Iwao
ad6c210c2b
CI: Run FreeBSD CI via GitHub Actions
...
Resolves: #3797
2026-04-28 11:47:13 +09:00
Koichiro Iwao
e6f350ae1a
CI: Remove Cirrus CI as the service is shutting down
2026-04-28 11:45:25 +09:00