mirror of
https://github.com/X11Libre/xserver.git
synced 2026-09-27 21:22:26 +00:00
record: Prevent out of bounds access when recording a reply.
Any pad bytes in replies are written to the client from a zeroed array. However, record extension tries to incorrectly access the pad bytes from the end of reply data. Signed-off-by: Rami Ylimäki <rami.ylimaki@vincit.fi> Reviewed-by: Erkki Seppälä <erkki.seppala@vincit.fi>
This commit is contained in:
parent
1f5baa924a
commit
c1bb8f43b9
3 changed files with 33 additions and 24 deletions
|
|
@ -451,9 +451,10 @@ extern _X_EXPORT CallbackListPtr ReplyCallback;
|
|||
typedef struct {
|
||||
ClientPtr client;
|
||||
const void *replyData;
|
||||
unsigned long dataLenBytes;
|
||||
unsigned long dataLenBytes; /* actual bytes from replyData + pad bytes */
|
||||
unsigned long bytesRemaining;
|
||||
Bool startOfReply;
|
||||
unsigned long padBytes; /* pad bytes from zeroed array */
|
||||
} ReplyInfoRec;
|
||||
|
||||
/* stuff for FlushCallback */
|
||||
|
|
|
|||
Loading…
Reference in a new issue