Bug#1143110: Heap buffer overflow in rdp_monitor.c → crash (SEGV/ABRT) when connecting with 2+ monitors

Andreas Ziegler <[email protected]>
Newsgroups gmane.linux.debian.devel.bugs.rc
Message-ID <2c553e88575aa1fde1c298d308953e68__21599.0711980098$1785420199$gmane$org@conemu.de>
Package: remmina
Version: 1.4.39+dfsg-1+deb13u1
Severity: grave
Tags: security upstream patch

Dear Maintainer,

Remmina 1.4.39 in Debian 13 (trixie) has a heap buffer overflow in the 
RDP plugin that causes a reliable crash (SEGV/ABRT) when connecting to 
any RDP server with 2+ physical monitors.

## Root cause

In `plugins/rdp/rdp_monitor.c`, `remmina_rdp_monitor_get()` fetches a 
pointer to FreeRDP's internal `MonitorDefArray` and writes monitor data 
directly to it:

```c
rdpMonitor* base = (rdpMonitor *)freerdp_settings_get_pointer(settings, 
FreeRDP_MonitorDefArray);
// ...
current = &base[index];  // index can exceed the array size
```

During `PreConnect`, FreeRDP's 
`freerdp_settings_enforce_monitor_exists()` shrinks this array to 1 
element when `multimon=0`. When Remmina writes `base[1]` (second 
monitor), it overflows into adjacent heap memory.

The overflow writes `rdpMonitor` struct fields (`orig_screen` + 
`physicalWidth`) which combine to form a bogus pointer (`0x25400000001` 
where `0x254` = 596 = the monitor's physical width in mm). Dereferencing 
this pointer causes SEGV; glibc's `free()` detecting the corruption 
causes ABRT.

## Reproduction

1. System with 2+ physical monitors
2. `remmina 1.4.39+dfsg-1+deb13u1`, `freerdp3 3.15.0+dfsg-2.1+deb13u3`, 
Debian 13 trixie
3. Any RDP profile with `multimon=0` (default)
4. Connect → crash within seconds

Kernel log:
```
kernel: RemmRDP:FINDesk[25840]: segfault at 25400000001 ip ... in 
libc.so.6
```

## Affected Debian suites

- **trixie**: 1.4.39+dfsg-1+deb13u1 — **affected** (confirmed crash)
- **sid/forky**: 1.4.43+dfsg-1 — **not affected** (already uses local 
calloc, no direct write)
- **bookworm**: 1.4.29+dfsg-1 — unknown, may be affected (uses older 
code)
- **bullseye**: 1.4.11+dfsg-3 — unknown, may be affected (uses older 
code)

## Fix

Already fixed in Remmina upstream master (and in sid 1.4.43). The fix:
1. Allocates a local array (`calloc(n_monitors + 1, 
sizeof(rdpMonitor))`)
2. Writes monitor data to the local array instead of FreeRDP's internal 
array
3. Uses `freerdp_settings_set_monitor_def_array_sorted()` to properly 
copy into FreeRDP settings

Upstream issues:
- https://gitlab.com/Remmina/Remmina/-/work_items/3558 (settings 
ignored)
- https://gitlab.com/Remmina/Remmina/-/merge_requests/2768 (related 
cleanup MR)
- https://github.com/FreeRDP/FreeRDP/issues/13122 (FreeRDP side: array 
reallocation)
- https://github.com/FreeRDP/FreeRDP/pull/13123 (FreeRDP fix PR)

## Request

Please backport the upstream fix to the trixie package. The relevant 
change rewrites `remmina_rdp_monitor_get()` in 
`plugins/rdp/rdp_monitor.c` to use a local array instead of writing 
directly to FreeRDP's `MonitorDefArray`.

The fix is already in Remmina master / sid and does not affect FreeRDP 
(no FreeRDP changes needed).

Note: `xfreerdp3` (also in Debian) is NOT affected — only Remmina's RDP 
plugin has the direct-write pattern.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.