Skip to content

Bind KdRelay to loopback - #41260

Merged
Ben Hillis (benhillis) merged 1 commit into
microsoft:masterfrom
benhillis:user/benhill/bind-kd-relay-loopback
Aug 6, 2026
Merged

Ben Hillis (benhillis) merged 1 commit into
microsoft:masterfrom
benhillis:user/benhill/bind-kd-relay-loopback

Conversation

@benhillis

@benhillis Ben Hillis (benhillis) commented Aug 5, 2026 •

Copy link
Copy Markdown
Member

Restrict the KdRelay listener to local connections by binding to the loopback address instead of the wildcard address.

Restrict the KdRelay listener to local connections.

Co-authored-by: Copilot <[email protected]>

Copilot-Session: d9d1a097-a7bc-4c1b-806b-d3778adfd23a
@benhillis
Ben Hillis (benhillis) requested a review from a team as a code owner August 5, 2026 19:52
Copilot AI lite review requested due to automatic review settings August 5, 2026 19:52

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR hardens wslrelay’s KdRelay mode by limiting the TCP listener to local-only connections, binding the socket to the loopback interface instead of all interfaces. This reduces the exposed attack surface while keeping the relay behavior otherwise unchanged.

Changes:

  • Bind the KdRelay AF_INET listening socket to INADDR_LOOPBACK (127.0.0.1) rather than INADDR_ANY.

@benhillis
Ben Hillis (benhillis) merged commit 5eb2138 into microsoft:master Aug 6, 2026
9 checks passed
Ben Hillis (benhillis) added a commit that referenced this pull request Sep 8, 2026
Restrict the KdRelay listener to local connections.

Co-authored-by: Copilot <[email protected]>

Co-authored-by: Ben Hillis <[email protected]>
Copilot-Session: d9d1a097-a7bc-4c1b-806b-d3778adfd23a
(cherry picked from commit 5eb2138)
Ben Hillis (benhillis) added a commit that referenced this pull request Sep 10, 2026
* Validate NUL-termination of flexible-array Buffer in interop messages (#40402)

* Validate NUL-termination of flexible-array Buffer in interop messages

Use string::FromMessageBuffer<T>() instead of directly accessing the
Buffer[] flexible-array member in interop message structs. FromMessageBuffer
validates that a NUL terminator exists within the span bounds, preventing
out-of-bounds reads when a malformed message contains no Buffer data or
lacks NUL termination.

Affected message handlers:
- LxInitMessageQueryEnvironmentVariable (config.cpp)
- LxInitMessageCreateLoginSession (config.cpp)
- LxMiniInitMessageUnmount (main.cpp)

Co-authored-by: Copilot <[email protected]>

* Remove unused Message parameter name in WSLC_UNMOUNT handler

After switching to FromMessageBuffer, the Message parameter is no longer
referenced directly. Remove the name to avoid -Wunused-parameter.

Co-authored-by: Copilot <[email protected]>

---------

Co-authored-by: Ben Hillis <[email protected]>
Co-authored-by: Copilot <[email protected]>
(cherry picked from commit 909d5eb)

* Bind KdRelay to loopback (#41260)

Restrict the KdRelay listener to local connections.

Co-authored-by: Copilot <[email protected]>

Co-authored-by: Ben Hillis <[email protected]>
Copilot-Session: d9d1a097-a7bc-4c1b-806b-d3778adfd23a
(cherry picked from commit 5eb2138)

* Update Microsoft.NETCore.App.Runtime to 10.0.11 (#41332)

(cherry picked from commit 8edd976)

* Fix unvalidated TerminalProfileSize during distribution import (#41495)

* Fix unvalidated TerminalProfileSize when importing a distribution

_ProcessImportResultMessage constructed the terminal profile string_view
using the message-supplied TerminalProfileSize without validating it
against the received buffer length. Use the bounds-checked two-argument
span::subspan() overload (matching the existing ShortcutIconSize handling
a few lines above) so an inconsistent size value throws instead of
producing a string_view that runs past the end of the buffer.

Co-authored-by: Copilot <[email protected]>
Copilot-Session: 35281c30-3d08-4f05-8c84-2ce4711023d5

* format source

---------

Co-authored-by: Ben Hillis <[email protected]>
Co-authored-by: Copilot <[email protected]>
Copilot-Session: 35281c30-3d08-4f05-8c84-2ce4711023d5
(cherry picked from commit f2d87e0)

* Avoid stop service race window during uninstall (#40625)

Disable service before stopping service during uninstall.

(cherry picked from commit c28bd15)

---------

Co-authored-by: Ben Hillis <[email protected]>
Co-authored-by: Copilot <[email protected]>
Co-authored-by: Blue <[email protected]>
Co-authored-by: Feng Wang <[email protected]>
Copilot-Session: d9d1a097-a7bc-4c1b-806b-d3778adfd23a
Copilot-Session: 35281c30-3d08-4f05-8c84-2ce4711023d5
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants