SIGN IN SIGN UP

libvncclient: add bounds checks to UltraZip subrectangle parsing

HandleUltraZipBPP() iterates over sub-rectangles using numCacheRects
(derived from the attacker-controlled rect.r.x) without validating
that the pointer stays within the decompressed data buffer. A malicious
server can set a large numCacheRects value, causing heap out-of-bounds
reads via the memcpy calls in the parsing loop.

Add bounds checks before reading the 12-byte subrect header and before
advancing the pointer by the raw pixel data size. Use uint64_t for the
raw data size calculation to prevent integer overflow on 32-bit platforms.
K
Kazuma Matsumoto committed
009008e2f4d5a54dd71f422070df3af7b3dbc931
Parent: dc78dee
Committed by Christian Beier <info@christianbeier.net> on 3/22/2026, 7:35:49 PM