mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-09-27 12:30:34 -09:00
Patches mostly backported with the basis of the work of Ubuntu Security
team. See [1].
Fix the following vulnerabilities:
- CVE-2024-32661:
FreeRDP is a free implementation of the Remote Desktop Protocol.
FreeRDP based clients prior to version 3.5.1 are vulnerable to a
possible `NULL` access and crash. Version 3.5.1 contains a patch for
the issue. No known workarounds are available.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2024-32661
- CVE-2026-23530:
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior
to version 3.21.0,`freerdp_bitmap_decompress_planar` does not validate
`nSrcWidth`/`nSrcHeight` against `planar->maxWidth`/`maxHeight` before
RLE decode. A malicious server can trigger a client‑side heap buffer
overflow, causing a crash (DoS) and potential heap corruption with
code‑execution risk depending on allocator behavior and surrounding
heap layout. Version 3.21.0 contains a patch for the issue.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2026-23530
- CVE-2026-23531:
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior
to version 3.21.0, in ClearCodec, when `glyphData` is present,
`clear_decompress` calls `freerdp_image_copy_no_overlap` without
validating the destination rectangle, allowing an out-of-bounds
read/write via crafted RDPGFX surface updates. A malicious server can
trigger a client‑side heap buffer overflow, causing a crash (DoS) and
potential heap corruption with code‑execution risk depending on
allocator behavior and surrounding heap layout. Version 3.21.0
contains a patch for the issue.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2026-23531
- CVE-2026-23532:
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior
to version 3.21.0, a client-side heap buffer overflow occurs in the
FreeRDP client’s `gdi_SurfaceToSurface` path due to a mismatch between
destination rectangle clamping and the actual copy size. A malicious
server can trigger a client‑side heap buffer overflow, causing a crash
(DoS) and potential heap corruption with code‑execution risk depending
on allocator behavior and surrounding heap layout. Version 3.21.0
contains a patch for the issue.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2026-23532
- CVE-2026-23533:
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior
to version 3.21.0, a client-side heap buffer overflow occurs in the
RDPGFX ClearCodec decode path when maliciously crafted residual data
causes out-of-bounds writes during color output. A malicious server
can trigger a client‑side heap buffer overflow, causing a crash (DoS)
and potential heap corruption with code‑execution risk depending on
allocator behavior and surrounding heap layout. Version 3.21.0
contains a patch for the issue.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2026-23533
- CVE-2026-23534:
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior
to version 3.21.0, a client-side heap buffer overflow occurs in the
ClearCodec bands decode path when crafted band coordinates allow
writes past the end of the destination surface buffer. A malicious
server can trigger a client‑side heap buffer overflow, causing a crash
(DoS) and potential heap corruption with code‑execution risk depending
on allocator behavior and surrounding heap layout. Version 3.21.0
contains a patch for the issue.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2026-23534
- CVE-2026-23948:
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior
to 3.22.0, a NULL pointer dereference vulnerability in
rdp_write_logon_info_v2() allows a malicious RDP server to crash
FreeRDP proxy by sending a specially crafted LogonInfoV2 PDU with
cbDomain=0 or cbUserName=0. This vulnerability is fixed in 3.22.0.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2026-23948
- CVE-2026-24675:
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior
to 3.22.0, urb_select_interface can free the device's MS config on
error but later code still dereferences it, leading to a use after
free in libusb_udev_select_interface. This vulnerability is fixed in
3.22.0.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2026-24675
- CVE-2026-24676:
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior
to 3.22.0, AUDIN format renegotiation frees the active format list
while the capture thread continues using audin->format, leading to a
use after free in audio_format_compatible. This vulnerability is fixed
in 3.22.0.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2026-24676
- CVE-2026-24679:
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior
to 3.22.0, The URBDRC client uses server-supplied interface numbers as
array indices without bounds checks, causing an out-of-bounds read in
libusb_udev_select_interface. This vulnerability is fixed in 3.22.0.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2026-24679
- CVE-2026-24681:
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior
to 3.22.0, aAsynchronous bulk transfer completions can use a freed
channel callback after URBDRC channel close, leading to a use after
free in urb_write_completion. This vulnerability is fixed in 3.22.0.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2026-24681
- CVE-2026-24682:
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior
to 3.22.0, audin_server_recv_formats frees an incorrect number of
audio formats on parse failure (i + i), leading to out-of-bounds
access in audio_formats_free. This vulnerability is fixed in 3.22.0.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2026-24682
- CVE-2026-24683:
FreeRDP is a free implementation of the Remote Desktop Protocol.
ainput_send_input_event caches channel_callback in a local variable
and later uses it without synchronization; a concurrent channel close
can free or reinitialize the callback, leading to a use after free.
Prior to 3.22.0, This vulnerability is fixed in 3.22.0.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2026-24683
[1] https://launchpad.net/ubuntu/+archive/primary/+sourcefiles/freerdp2/2.6.1+dfsg1-3ubuntu2.10/freerdp2_2.6.1+dfsg1-3ubuntu2.10.debian.tar.xz
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
117 lines
3.2 KiB
Diff
117 lines
3.2 KiB
Diff
From afa6851dc80835d3101e40fcef51b6c5c0f43ea5 Mon Sep 17 00:00:00 2001
|
|
From: akallabeth <akallabeth@posteo.net>
|
|
Date: Wed, 28 Jan 2026 09:31:06 +0100
|
|
Subject: [PATCH] [channel,rdpsnd] only clean up thread before free
|
|
|
|
rdpsnd channel usually has multiple instances (static, dynamic, ...) so
|
|
ensure only to terminate the handler thread when the channel is actually
|
|
closed for good.
|
|
|
|
CVE: CVE-2026-24684
|
|
Upstream: https://github.com/FreeRDP/FreeRDP/commit/afa6851dc80835d3101e40fcef51b6c5c0f43ea5
|
|
[thomas: backport https://launchpad.net/ubuntu/+archive/primary/+sourcefiles/freerdp2/2.6.1+dfsg1-3ubuntu2.10/freerdp2_2.6.1+dfsg1-3ubuntu2.10.debian.tar.xz]
|
|
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
|
|
---
|
|
channels/rdpsnd/client/rdpsnd_main.c | 43 ++++++++++++++++------------
|
|
1 file changed, 25 insertions(+), 18 deletions(-)
|
|
|
|
diff --git a/channels/rdpsnd/client/rdpsnd_main.c b/channels/rdpsnd/client/rdpsnd_main.c
|
|
index 61a29ec40aa8..5a1edaea62c6 100644
|
|
--- a/channels/rdpsnd/client/rdpsnd_main.c
|
|
+++ b/channels/rdpsnd/client/rdpsnd_main.c
|
|
@@ -132,6 +132,8 @@ struct rdpsnd_plugin
|
|
BOOL applyVolume;
|
|
};
|
|
|
|
+static DWORD WINAPI play_thread(LPVOID arg);
|
|
+
|
|
static const char* rdpsnd_is_dyn_str(BOOL dynamic)
|
|
{
|
|
if (dynamic)
|
|
@@ -1264,7 +1266,6 @@ static void cleanup_internals(rdpsndPlug
|
|
if (!rdpsnd)
|
|
return;
|
|
|
|
- rdpsnd_terminate_thread(rdpsnd);
|
|
if (rdpsnd->pool)
|
|
StreamPool_Return(rdpsnd->pool, rdpsnd->data_in);
|
|
|
|
@@ -1328,6 +1329,7 @@ static void free_internals(rdpsndPlugin*
|
|
if (!rdpsnd)
|
|
return;
|
|
|
|
+ rdpsnd_terminate_thread(rdpsnd);
|
|
freerdp_dsp_context_free(rdpsnd->dsp_context);
|
|
StreamPool_Free(rdpsnd->pool);
|
|
rdpsnd->pool = NULL;
|
|
@@ -1349,6 +1351,21 @@ static BOOL allocate_internals(rdpsndPlu
|
|
if (!rdpsnd->dsp_context)
|
|
return FALSE;
|
|
}
|
|
+ if (!rdpsnd->queue)
|
|
+ {
|
|
+ wObject obj = { 0 };
|
|
+
|
|
+ obj.fnObjectFree = _queue_free;
|
|
+ rdpsnd->queue = MessageQueue_New(&obj);
|
|
+ if (!rdpsnd->queue)
|
|
+ return CHANNEL_RC_NO_MEMORY;
|
|
+ }
|
|
+ if (!rdpsnd->thread)
|
|
+ {
|
|
+ rdpsnd->thread = CreateThread(NULL, 0, play_thread, rdpsnd, 0, NULL);
|
|
+ if (!rdpsnd->thread)
|
|
+ return CHANNEL_RC_INITIALIZATION_ERROR;
|
|
+ }
|
|
|
|
return TRUE;
|
|
}
|
|
@@ -1388,23 +1405,12 @@ static DWORD WINAPI play_thread(LPVOID a
|
|
|
|
static UINT rdpsnd_virtual_channel_event_initialized(rdpsndPlugin* rdpsnd)
|
|
{
|
|
- wObject obj = { 0 };
|
|
-
|
|
if (!rdpsnd)
|
|
return ERROR_INVALID_PARAMETER;
|
|
|
|
- obj.fnObjectFree = _queue_free;
|
|
- rdpsnd->queue = MessageQueue_New(&obj);
|
|
- if (!rdpsnd->queue)
|
|
- return CHANNEL_RC_NO_MEMORY;
|
|
-
|
|
if (!allocate_internals(rdpsnd))
|
|
return CHANNEL_RC_NO_MEMORY;
|
|
|
|
- rdpsnd->thread = CreateThread(NULL, 0, play_thread, rdpsnd, 0, NULL);
|
|
- if (!rdpsnd->thread)
|
|
- return CHANNEL_RC_INITIALIZATION_ERROR;
|
|
-
|
|
return CHANNEL_RC_OK;
|
|
}
|
|
|
|
@@ -1412,8 +1418,6 @@ void rdpsnd_virtual_channel_event_termin
|
|
{
|
|
if (rdpsnd)
|
|
{
|
|
- rdpsnd_terminate_thread(rdpsnd);
|
|
-
|
|
free_internals(rdpsnd);
|
|
audio_formats_free(rdpsnd->fixed_format, 1);
|
|
free(rdpsnd->subsystem);
|
|
@@ -1602,13 +1606,13 @@ static UINT rdpsnd_on_close(IWTSVirtualC
|
|
|
|
cleanup_internals(rdpsnd);
|
|
|
|
+ free_internals(rdpsnd);
|
|
if (rdpsnd->device)
|
|
{
|
|
IFCALL(rdpsnd->device->Free, rdpsnd->device);
|
|
rdpsnd->device = NULL;
|
|
}
|
|
|
|
- free_internals(rdpsnd);
|
|
free(pChannelCallback);
|
|
return CHANNEL_RC_OK;
|
|
}
|