mirror of
https://github.com/CalcProgrammer1/OpenRGB.git
synced 2026-09-13 13:47:02 -04:00
Address security issues in release_candidate_1.0rc3
- CVE-2026-59682: OpenRGB: arbitrary file overwrite and deletion local and remote - CVE-2026-59683: OpenRGB: local and remote system compromise via arbitrary file write using attacker controlled strings - CVE-2026-18794: OpenRGB: insufficient input data checks lead to Denial-of-Service, memory overread and overwrite
This commit is contained in:
1 parent
6fbcf62d76
commit
d2dd9dcc73
7 files changed
+61
-7
No files matched your search
+6
-1
@@ -627,7 +627,12 @@ void NetworkServer::ListenThreadFunction(NetworkClientInfo * client_info)
|
||||
| Header received, now receive the data |
|
||||
\*---------------------------------------------------------*/
|
||||
bytes_read = 0;
|
||||
if(header.pkt_size > 0)
|
||||
if(header.pkt_size > OPENRGB_SDK_MAX_PACKET_SIZE)
|
||||
{
|
||||
LOG_ERROR("[NetworkServer] received too large packet, closing listener");
|
||||
goto listen_done;
|
||||
}
|
||||
else if(header.pkt_size > 0)
|
||||
{
|
||||
data = new char[header.pkt_size];
|
||||
|
||||
|
||||
Reference in new issue
Block a user