fix(libvncserver): CVE-2026-32853 and CVE-2026-32854#3
Open
deepin-ci-robot wants to merge 3 commits intomasterfrom
Open
fix(libvncserver): CVE-2026-32853 and CVE-2026-32854#3deepin-ci-robot wants to merge 3 commits intomasterfrom
deepin-ci-robot wants to merge 3 commits intomasterfrom
Conversation
Fix heap out-of-bounds read in UltraZip encoding handler. HandleUltraZipBPP() iterates over sub-rectangles without validating that the pointer stays within the decompressed data buffer. A malicious server can set a large numCacheRects value, causing heap out-of-bounds reads. Upstream: LibVNC/libvncserver@009008e Generated-By: glm-5.1 Co-Authored-By: hudeng <hudeng@deepin.org>
Fix null pointer dereference in HTTP proxy handlers. httpProcessInput() passes the return value of strchr() to atoi() and strncmp() without checking for NULL. If a CONNECT request contains no colon, or a GET request contains no slash, strchr() returns NULL, leading to a segmentation fault. Upstream: LibVNC/libvncserver@dc78dee Generated-By: glm-5.1 Co-Authored-By: hudeng <hudeng@deepin.org>
Generated-By: glm-5.1 Co-Authored-By: hudeng <hudeng@deepin.org>
Contributor
Author
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
TAG Bot TAG: 0.9.14+dfsg-1deepin1 |
|
/integrate |
|
AutoIntegrationPr Bot |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
CVE 修复
CVE IDs: CVE-2026-32853, CVE-2026-32854
CVE-2026-32853
漏洞描述: Heap out-of-bounds read vulnerability in UltraZip encoding handler
影响版本: LibVNCServer 0.9.15 and prior
修复方案: Add bounds checks to UltraZip subrectangle parsing
上游链接: LibVNC/libvncserver@009008e
验证状态: ✅ Patches applied successfully, only debian/ modified
CVE-2026-32854
漏洞描述: NULL pointer dereference in HTTP proxy handlers
影响版本: LibVNCServer 0.9.15 and prior
修复方案: Add NULL checks before using strchr() return values
上游链接: LibVNC/libvncserver@dc78dee
验证状态: ✅ Patches applied successfully, only debian/ modified
修复方式: backport-upstream
Generated by: CVE-Fixer Agent
Co-Authored-By: hudeng hudeng@deepin.org