(release/25.0) Xi: bound SwapLongs of resolution values to the request length (backport to 25.0) - #3792
Conversation
…ort to 25.0) SProcXChangeDeviceControl() swapped "r->num_valuators" CARD32 in place after only checking that the request covered xDeviceResolutionCtl. With "num_valuators" being a CARD8 from the wire, a short request for DEVICE_RESOLUTION could byte-swap up to 1020 bytes past the end of the request buffer. Fix this issue by using the same extra-length check as ProcXChangeDeviceControl() before calling SwapLongs(). (cherry picked from commit 1fa7308)
Review: pass — verified security backport, faithful to masterI checked the claims in the description against the actual The vulnerability is real on 25.0
case DEVICE_RESOLUTION:
{
xDeviceResolutionCtl *r = (xDeviceResolutionCtl *) &stuff[1];
if (client->req_len - bytes_to_int32(sizeof(xChangeDeviceControlReq))
< bytes_to_int32(sizeof(xDeviceResolutionCtl)))
return BadLength;
SwapLongs((CARD32 *) (r + 1), r->num_valuators); /* unbounded */
break;
}
The fix matches
|
Backport of commit 1fa7308 to release/25.0.
SProcXChangeDeviceControl() swapped "r->num_valuators" CARD32 in place after only checking that the request covered xDeviceResolutionCtl.
With "num_valuators" being a CARD8 from the wire, a short request for DEVICE_RESOLUTION could byte-swap up to 1020 bytes past the end of the request buffer.
Fix this issue by using the same extra-length check as ProcXChangeDeviceControl() before calling SwapLongs().
Verknüpfung
Release merges are manual, by the maintainer.