All of lore.kernel.org
 help / color / mirror / Atom feed
From: ankur.tyagi85@gmail.com
To: openembedded-devel@lists.openembedded.org
Cc: Ankur Tyagi <ankur.tyagi85@gmail.com>
Subject: [oe][meta-oe][wrynose][PATCH 1/15] freerdp3: patch CVE-2026-40254
Date: Wed,  9 Sep 2026 20:31:26 +1200	[thread overview]
Message-ID: <20260909083140.2494932-1-ankur.tyagi85@gmail.com> (raw)

From: Ankur Tyagi <ankur.tyagi85@gmail.com>

Backport commits matching advisory[1] mentioned in the NVD.

Details:
https://nvd.nist.gov/vuln/detail/cve-2026-40254

[1]https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-3xpj-m4hx-8vmx

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
 .../freerdp/freerdp3/CVE-2026-40254-1.patch   | 46 +++++++++++++++++++
 .../freerdp/freerdp3/CVE-2026-40254-2.patch   | 30 ++++++++++++
 .../freerdp/freerdp3_3.24.2.bb                |  5 +-
 3 files changed, 80 insertions(+), 1 deletion(-)
 create mode 100644 meta-oe/recipes-support/freerdp/freerdp3/CVE-2026-40254-1.patch
 create mode 100644 meta-oe/recipes-support/freerdp/freerdp3/CVE-2026-40254-2.patch

diff --git a/meta-oe/recipes-support/freerdp/freerdp3/CVE-2026-40254-1.patch b/meta-oe/recipes-support/freerdp/freerdp3/CVE-2026-40254-1.patch
new file mode 100644
index 0000000000..b758877882
--- /dev/null
+++ b/meta-oe/recipes-support/freerdp/freerdp3/CVE-2026-40254-1.patch
@@ -0,0 +1,46 @@
+From 11b850f6181cb607c7fa4ac7a4fa09d203e0aaf6 Mon Sep 17 00:00:00 2001
+From: Armin Novak <armin.novak@thincast.com>
+Date: Fri, 10 Apr 2026 08:45:55 +0200
+Subject: [PATCH] [channels,drive] refine bounds checks
+
+* better logging, fix wrong path component printed
+* ensure path does not end with path/..
+
+(cherry picked from commit f502dbb8462597fbe5b97f890359dfdecb525bf7)
+
+CVE: CVE-2026-40254
+Upstream-Status: Backport [https://github.com/FreeRDP/FreeRDP/commit/f502dbb8462597fbe5b97f890359dfdecb525bf7]
+
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ channels/drive/client/drive_file.c | 9 +++++----
+ 1 file changed, 5 insertions(+), 4 deletions(-)
+
+diff --git a/channels/drive/client/drive_file.c b/channels/drive/client/drive_file.c
+index 8ea7552a7..3d87d8e6b 100644
+--- a/channels/drive/client/drive_file.c
++++ b/channels/drive/client/drive_file.c
+@@ -113,6 +113,8 @@ static BOOL contains_dotdot(const WCHAR* path, size_t base_length, size_t path_l
+ 				if ((tst[2] == '/') || (tst[2] == '\\'))
+ 					return TRUE;
+ 			}
++			else
++				return TRUE;
+ 		}
+ 		tst += 2;
+ 	} while (TRUE);
+@@ -147,11 +149,10 @@ static WCHAR* drive_file_combine_fullpath(const WCHAR* base_path, const WCHAR* p
+ 		/* Ensure the path does not contain sequences like '..' */
+ 		if (contains_dotdot(&fullpath[base_path_length], base_path_length, PathWCharLength))
+ 		{
+-			char abuffer[MAX_PATH] = WINPR_C_ARRAY_INIT;
+-			(void)ConvertWCharToUtf8(&fullpath[base_path_length], abuffer, ARRAYSIZE(abuffer));
+-
++			char* abuffer = ConvertWCharToUtf8Alloc(&fullpath[base_path_length], nullptr);
+ 			WLog_WARN(TAG, "[rdpdr] received invalid file path '%s' from server, aborting!",
+-			          &abuffer[base_path_length]);
++			          abuffer);
++			free(abuffer);
+ 			goto fail;
+ 		}
+ 	}
diff --git a/meta-oe/recipes-support/freerdp/freerdp3/CVE-2026-40254-2.patch b/meta-oe/recipes-support/freerdp/freerdp3/CVE-2026-40254-2.patch
new file mode 100644
index 0000000000..ac727b5235
--- /dev/null
+++ b/meta-oe/recipes-support/freerdp/freerdp3/CVE-2026-40254-2.patch
@@ -0,0 +1,30 @@
+From 3b1f9e5690d60c6a070e40587c5b23e56b172684 Mon Sep 17 00:00:00 2001
+From: Sayed Kaif <metsw24@gmail.com>
+Date: Sun, 28 Jun 2026 16:55:01 +0530
+Subject: [PATCH] [channels,drive] reject trailing '..' in contains_dotdot
+
+The trailing '..' check never fired because PathLength counts the NUL terminator, leaving path_length one WCHAR longer than the string; treat '\0' as a component terminator so a final '..' is rejected like '../'.
+
+(cherry picked from commit 17543c9ae0a72a5413e19741cf0203ab519fb3fd)
+
+CVE: CVE-2026-40254
+Upstream-Status: Backport [https://github.com/FreeRDP/FreeRDP/commit/17543c9ae0a72a5413e19741cf0203ab519fb3fd]
+
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ channels/drive/client/drive_file.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/channels/drive/client/drive_file.c b/channels/drive/client/drive_file.c
+index 3d87d8e6b..fa93946e2 100644
+--- a/channels/drive/client/drive_file.c
++++ b/channels/drive/client/drive_file.c
+@@ -110,7 +110,7 @@ static BOOL contains_dotdot(const WCHAR* path, size_t base_length, size_t path_l
+ 		{
+ 			if (tst + 2 < path + path_length)
+ 			{
+-				if ((tst[2] == '/') || (tst[2] == '\\'))
++				if ((tst[2] == '/') || (tst[2] == '\\') || (tst[2] == '\0'))
+ 					return TRUE;
+ 			}
+ 			else
diff --git a/meta-oe/recipes-support/freerdp/freerdp3_3.24.2.bb b/meta-oe/recipes-support/freerdp/freerdp3_3.24.2.bb
index a4561495cf..7164a81e9d 100644
--- a/meta-oe/recipes-support/freerdp/freerdp3_3.24.2.bb
+++ b/meta-oe/recipes-support/freerdp/freerdp3_3.24.2.bb
@@ -10,7 +10,10 @@ inherit pkgconfig cmake ptest
 
 SRCREV = "3028b706908f81767d9b9c744a90778c28f57d61"
 SRC_URI = "git://github.com/FreeRDP/FreeRDP.git;nobranch=1;protocol=https;tag=${PV} \
-           file://run-ptest"
+           file://run-ptest \
+           file://CVE-2026-40254-1.patch \
+           file://CVE-2026-40254-2.patch \
+"
 
 
 CVE_PRODUCT = "freerdp"


             reply	other threads:[~2026-09-09  8:31 UTC|newest]

Thread overview: 15+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-09  8:31 ankur.tyagi85 [this message]
2026-09-09  8:31 ` [oe][meta-oe][wrynose][PATCH 2/15] freerdp3: patch CVE-2026-55191 ankur.tyagi85
2026-09-09  8:31 ` [oe][meta-oe][wrynose][PATCH 3/15] freerdp3: patch CVE-2026-55192 ankur.tyagi85
2026-09-09  8:31 ` [oe][meta-oe][wrynose][PATCH 4/15] freerdp3: patch CVE-2026-55193 ankur.tyagi85
2026-09-09  8:31 ` [oe][meta-oe][wrynose][PATCH 5/15] freerdp3: patch CVE-2026-55194 ankur.tyagi85
2026-09-09  8:31 ` [oe][meta-oe][wrynose][PATCH 6/15] freerdp3: patch CVE-2026-55564 ankur.tyagi85
2026-09-09  8:31 ` [oe][meta-oe][wrynose][PATCH 7/15] freerdp3: patch CVE-2026-55648 ankur.tyagi85
2026-09-09  8:31 ` [oe][meta-oe][wrynose][PATCH 8/15] freerdp3: patch CVE-2026-63633 ankur.tyagi85
2026-09-09  8:31 ` [oe][meta-oe][wrynose][PATCH 9/15] freerdp3: patch CVE-2026-63652 ankur.tyagi85
2026-09-09  8:31 ` [oe][meta-oe][wrynose][PATCH 10/15] freerdp3: patch CVE-2026-64620 ankur.tyagi85
2026-09-09  8:31 ` [oe][meta-oe][wrynose][PATCH 11/15] freerdp3: patch CVE-2026-64621 ankur.tyagi85
2026-09-09  8:31 ` [oe][meta-oe][wrynose][PATCH 12/15] freerdp3: patch CVE-2026-66401 ankur.tyagi85
2026-09-09  8:31 ` [oe][meta-oe][wrynose][PATCH 13/15] freerdp3: patch CVE-2026-67288 ankur.tyagi85
2026-09-09  8:31 ` [oe][meta-python][wrynose][PATCH 14/15] python3-gunicorn: mark CVE-2024-1135 patched ankur.tyagi85
2026-09-09  8:31 ` [oe][meta-python][wrynose][PATCH 15/15] python3-h11: mark CVE-2025-43859 patched ankur.tyagi85

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260909083140.2494932-1-ankur.tyagi85@gmail.com \
    --to=ankur.tyagi85@gmail.com \
    --cc=openembedded-devel@lists.openembedded.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.