Fix incorrect bounds checks in planar codec (CVE-2026-45700)

Backport upstream commit 4a065a941 to fix CVE-2026-45700 in
freerdp 2.11.7. The patch corrects incorrect bounds checks in the
planar codec's RLE decompression path where nDstStep was used
instead of nTempStep, both in the bounds check condition and the
corresponding error message in planar_decompress().

CVE: CVE-2026-45700
Upstream patches:
 - 4a065a941a.patch
Resolves: RHEL-186983

This commit was backported by Ymir, a Red Hat Enterprise Linux software maintenance AI agent.

Assisted-by: Ymir
This commit is contained in:
RHEL Packaging Agent 2026-06-24 15:12:47 +00:00 committed by Ondrej Holy
parent 1b5392d4b1
commit 5dd7f31d75
2 changed files with 40 additions and 1 deletions

View File

@ -0,0 +1,31 @@
From 836d5b6f6d305ba6542fac8ba2d16b2e4e8b13a7 Mon Sep 17 00:00:00 2001
From: Armin Novak <armin.novak@thincast.com>
Date: Thu, 30 Apr 2026 15:03:21 +0200
Subject: [PATCH] [codec,planar] fix bounds checks
---
libfreerdp/codec/planar.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/libfreerdp/codec/planar.c b/libfreerdp/codec/planar.c
index 9b4d13057..67fc4212e 100644
--- a/libfreerdp/codec/planar.c
+++ b/libfreerdp/codec/planar.c
@@ -841,12 +841,12 @@ BOOL planar_decompress(BITMAP_PLANAR_CONTEXT* planar, const BYTE* pSrcData, UINT
return FALSE;
}
- if ((nXDst + nSrcWidth) * bpp > nDstStep)
+ if ((nXDst + nSrcWidth) * bpp > nTempStep)
{
WLog_ERR(TAG,
"planar plane destination (X %" PRIu32 " + width %" PRIu32
") * bpp %" PRIu32 " exceeds stride %" PRIu32,
- nXDst, nSrcWidth, bpp, nDstStep);
+ nXDst, nSrcWidth, bpp, nTempStep);
return FALSE;
}
--
2.52.0

View File

@ -27,7 +27,7 @@
Name: freerdp
Version: 2.11.7
Release: 9%{?dist}
Release: 10%{?dist}
Epoch: 2
Summary: Free implementation of the Remote Desktop Protocol (RDP)
License: ASL 2.0
@ -191,6 +191,10 @@ Patch43: client-x11-improve-rails-window-locking.patch
Patch44: client-x11-refactor-locking.patch
Patch45: client-x11-fix-deadlock-on-output-expose.patch
# CVE-2026-45700
# https://github.com/FreeRDP/FreeRDP/commit/4a065a941ae134a0433d1497c03b3c3eb91b9f85
Patch46: codec-planar-fix-bounds-checks.patch
BuildRequires: gcc
BuildRequires: gcc-c++
BuildRequires: alsa-lib-devel
@ -448,6 +452,10 @@ find %{buildroot} -name "*.a" -delete
%{_libdir}/pkgconfig/winpr-tools2.pc
%changelog
* Wed Jun 24 2026 RHEL Packaging Agent <rhel-se-jotnar@redhat.com> - 2:2.11.7-10
- Fix incorrect bounds checks in planar codec (CVE-2026-45700)
Resolves: RHEL-186983
* Tue May 05 2026 Ondrej Holy <oholy@redhat.com> - 2:2.11.7-9
- Lock appWindow to fix use-after-free in RAIL mode (CVE-2026-25952)
Resolves: RHEL-159850