Package: remmina
Version: 1.4.39+dfsg-1+deb13u1
Severity: grave
Tags: security upstream patch

Dear Maintainer,

Remmina 1.4.39 in Debian 13 (trixie) has a heap buffer overflow in the RDP plugin that causes a reliable crash (SEGV/ABRT) when connecting to any RDP server with 2+ physical monitors.

## Root cause

In `plugins/rdp/rdp_monitor.c`, `remmina_rdp_monitor_get()` fetches a pointer to FreeRDP's internal `MonitorDefArray` and writes monitor data directly to it:

```c
rdpMonitor* base = (rdpMonitor *)freerdp_settings_get_pointer(settings, FreeRDP_MonitorDefArray);
// ...
current = &base[index];  // index can exceed the array size
```

During `PreConnect`, FreeRDP's `freerdp_settings_enforce_monitor_exists()` shrinks this array to 1 element when `multimon=0`. When Remmina writes `base[1]` (second monitor), it overflows into adjacent heap memory.

The overflow writes `rdpMonitor` struct fields (`orig_screen` + `physicalWidth`) which combine to form a bogus pointer (`0x25400000001` where `0x254` = 596 = the monitor's physical width in mm). Dereferencing this pointer causes SEGV; glibc's `free()` detecting the corruption causes ABRT.

## Reproduction

1. System with 2+ physical monitors
2. `remmina 1.4.39+dfsg-1+deb13u1`, `freerdp3 3.15.0+dfsg-2.1+deb13u3`, Debian 13 trixie
3. Any RDP profile with `multimon=0` (default)
4. Connect → crash within seconds

Kernel log:
```
kernel: RemmRDP:FINDesk[25840]: segfault at 25400000001 ip ... in libc.so.6
```

## Affected Debian suites

- **trixie**: 1.4.39+dfsg-1+deb13u1 — **affected** (confirmed crash)
- **sid/forky**: 1.4.43+dfsg-1 — **not affected** (already uses local calloc, no direct write) - **bookworm**: 1.4.29+dfsg-1 — unknown, may be affected (uses older code) - **bullseye**: 1.4.11+dfsg-3 — unknown, may be affected (uses older code)

## Fix

Already fixed in Remmina upstream master (and in sid 1.4.43). The fix:
1. Allocates a local array (`calloc(n_monitors + 1, sizeof(rdpMonitor))`) 2. Writes monitor data to the local array instead of FreeRDP's internal array 3. Uses `freerdp_settings_set_monitor_def_array_sorted()` to properly copy into FreeRDP settings

Upstream issues:
- https://gitlab.com/Remmina/Remmina/-/work_items/3558 (settings ignored) - https://gitlab.com/Remmina/Remmina/-/merge_requests/2768 (related cleanup MR) - https://github.com/FreeRDP/FreeRDP/issues/13122 (FreeRDP side: array reallocation)
- https://github.com/FreeRDP/FreeRDP/pull/13123 (FreeRDP fix PR)

## Request

Please backport the upstream fix to the trixie package. The relevant change rewrites `remmina_rdp_monitor_get()` in `plugins/rdp/rdp_monitor.c` to use a local array instead of writing directly to FreeRDP's `MonitorDefArray`.

The fix is already in Remmina master / sid and does not affect FreeRDP (no FreeRDP changes needed).

Note: `xfreerdp3` (also in Debian) is NOT affected — only Remmina's RDP plugin has the direct-write pattern.

Reply via email to