libvncclient: add bounds checks to UltraZip subrectangle parsing
HandleUltraZipBPP() iterates over sub-rectangles using numCacheRects (derived from the attacker-controlled rect.r.x) without validating that the pointer stays within the decompressed data buffer. A malicious server can set a large numCacheRects value, causing heap out-of-bounds reads via the memcpy calls in the parsing loop. Add bounds checks before reading the 12-byte subrect header and before advancing the pointer by the raw pixel data size. Use uint64_t for the raw data size calculation to prevent integer overflow on 32-bit platforms.
K
Kazuma Matsumoto committed
009008e2f4d5a54dd71f422070df3af7b3dbc931
Parent: dc78dee
Committed by Christian Beier <info@christianbeier.net>
on 3/22/2026, 7:35:49 PM