diff --git a/meta-oe/recipes-support/freerdp/freerdp3/CVE-2026-64620.patch b/meta-oe/recipes-support/freerdp/freerdp3/CVE-2026-64620.patch new file mode 100644 index 0000000000..e154a92499 --- /dev/null +++ b/meta-oe/recipes-support/freerdp/freerdp3/CVE-2026-64620.patch @@ -0,0 +1,37 @@ +From c04d10f9586ce92d7a7a3307744e16d554e20cfd Mon Sep 17 00:00:00 2001 +From: Armin Novak +Date: Thu, 2 Jul 2026 08:02:26 +0200 +Subject: [PATCH] [crypto] fix out buffer check + +(cherry picked from commit 27014741a8c22a34d3040c559c82f4ed82841bef) + +CVE: CVE-2026-64620 +Upstream-Status: Backport [https://github.com/FreeRDP/FreeRDP/commit/27014741a8c22a34d3040c559c82f4ed82841bef] + +Signed-off-by: Ankur Tyagi +--- + libfreerdp/crypto/crypto.c | 9 ++++++--- + 1 file changed, 6 insertions(+), 3 deletions(-) + +diff --git a/libfreerdp/crypto/crypto.c b/libfreerdp/crypto/crypto.c +index 3d210f2d9..60f7c6cee 100644 +--- a/libfreerdp/crypto/crypto.c ++++ b/libfreerdp/crypto/crypto.c +@@ -103,11 +103,14 @@ static SSIZE_T crypto_rsa_common(const BYTE* input, size_t length, UINT32 key_le + goto fail; + if (BN_mod_exp(y, x, exp, mod, ctx) != 1) + goto fail; +- output_length = BN_bn2bin(y, output); ++ { ++ const int len = BN_num_bytes(y); ++ if ((len < 0) || (WINPR_ASSERTING_INT_CAST(size_t, len) > out_length)) ++ goto fail; ++ output_length = BN_bn2bin(y, output); ++ } + if (output_length < 0) + goto fail; +- if (WINPR_ASSERTING_INT_CAST(size_t, output_length) > out_length) +- goto fail; + crypto_reverse(output, WINPR_ASSERTING_INT_CAST(size_t, output_length)); + + if ((size_t)output_length < key_length) diff --git a/meta-oe/recipes-support/freerdp/freerdp3_3.24.2.bb b/meta-oe/recipes-support/freerdp/freerdp3_3.24.2.bb index 86999ffe94..a577916bef 100644 --- a/meta-oe/recipes-support/freerdp/freerdp3_3.24.2.bb +++ b/meta-oe/recipes-support/freerdp/freerdp3_3.24.2.bb @@ -21,6 +21,7 @@ SRC_URI = "git://github.com/FreeRDP/FreeRDP.git;nobranch=1;protocol=https;tag=${ file://CVE-2026-55648.patch \ file://CVE-2026-63633.patch \ file://CVE-2026-63652.patch \ + file://CVE-2026-64620.patch \ "