Skip to content

[release/2.7] Backport additional fixes - #41540

Merged
Ben Hillis (benhillis) merged 5 commits into
release/2.7from
backport-security-fixes-release-2.7
Sep 10, 2026
Merged

Ben Hillis (benhillis) merged 5 commits into
release/2.7from
backport-security-fixes-release-2.7

Conversation

@benhillis

@benhillis Ben Hillis (benhillis) commented Sep 8, 2026 •

Copy link
Copy Markdown
Member

Backports the following security and servicing fixes from master to release/2.7:

Backport adaptations:

Validation:

  • cmake --build . --target init wslservice wslrelay wsl wslinstall -- -m
  • The full build compiles all affected targets but remains blocked by the existing wslserviceproxystub unresolved WSLCCompat_ProxyFileInfo / wslc_ProxyFileInfo symbols on this release checkout.

…#40402)

* Validate NUL-termination of flexible-array Buffer in interop messages

Use string::FromMessageBuffer<T>() instead of directly accessing the
Buffer[] flexible-array member in interop message structs. FromMessageBuffer
validates that a NUL terminator exists within the span bounds, preventing
out-of-bounds reads when a malformed message contains no Buffer data or
lacks NUL termination.

Affected message handlers:
- LxInitMessageQueryEnvironmentVariable (config.cpp)
- LxInitMessageCreateLoginSession (config.cpp)
- LxMiniInitMessageUnmount (main.cpp)

Co-authored-by: Copilot <[email protected]>

* Remove unused Message parameter name in WSLC_UNMOUNT handler

After switching to FromMessageBuffer, the Message parameter is no longer
referenced directly. Remove the name to avoid -Wunused-parameter.

Co-authored-by: Copilot <[email protected]>

---------

Co-authored-by: Ben Hillis <[email protected]>
Co-authored-by: Copilot <[email protected]>
(cherry picked from commit 909d5eb)
Copilot AI lite review requested due to automatic review settings September 8, 2026 17:16
@benhillis
Ben Hillis (benhillis) requested a review from a team as a code owner September 8, 2026 17:16

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

It backports multiple security-sensitive changes across networking and init message parsing, where subtle behavioral differences on the release branch warrant final human review.

Pull request overview

This PR backports a set of security and defense-in-depth fixes from master to the release/2.7 branch across Linux init message handling, mirrored networking port allocation, KdRelay binding behavior, distribution import parsing, and the bundled .NET runtime.

Changes:

  • Harden Linux init interop message parsing by validating NUL-termination for flexible-array Buffer[] fields via string::FromMessageBuffer<T>().
  • Prevent mirrored-network guest binds to ports in the host ephemeral port range (except where the port is within the guest’s reserved ephemeral range), and add mirrored-mode tests to validate the denial behavior.
  • Restrict KdRelay (wslrelay) listener binding to loopback, validate TerminalProfileSize against the import-result buffer, and update the bundled .NET runtime packages to 10.0.11.
File summaries
File Description
test/windows/NetworkTests.cpp Adds mirrored-mode tests verifying guest binds into the host ephemeral port range are denied (TCP/UDP).
src/windows/wslrelay/main.cpp Binds the listener to INADDR_LOOPBACK to restrict access to local connections.
src/windows/service/exe/WslCoreGuestNetworkService.h Introduces helpers/state for checking host/guest ephemeral port ranges.
src/windows/service/exe/WslCoreGuestNetworkService.cpp Queries host ephemeral ranges via WMI at startup and denies guest binds into the host range unless within the guest reserved range.
src/windows/service/exe/LxssUserSession.cpp Bounds-checks TerminalProfileSize when slicing the import-result buffer.
src/shared/inc/stringshared.h Adds FromMessageBuffer<T>() wrapper over FromSpan() using offsetof(T, Buffer) for flexible-array buffers.
src/linux/init/main.cpp Uses FromMessageBuffer for unmount message buffer parsing to ensure NUL-terminated access.
src/linux/init/config.cpp Uses FromMessageBuffer for environment-variable query and login-session creation messages to ensure NUL-terminated access.
packages.config Updates Microsoft.NETCore.App.Runtime win-x64/win-arm64 package versions to 10.0.11.
Review details
  • Files reviewed: 9/9 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Restrict the KdRelay listener to local connections.

Co-authored-by: Copilot <[email protected]>

Co-authored-by: Ben Hillis <[email protected]>
Copilot-Session: d9d1a097-a7bc-4c1b-806b-d3778adfd23a
(cherry picked from commit 5eb2138)
* Fix unvalidated TerminalProfileSize when importing a distribution

_ProcessImportResultMessage constructed the terminal profile string_view
using the message-supplied TerminalProfileSize without validating it
against the received buffer length. Use the bounds-checked two-argument
span::subspan() overload (matching the existing ShortcutIconSize handling
a few lines above) so an inconsistent size value throws instead of
producing a string_view that runs past the end of the buffer.

Co-authored-by: Copilot <[email protected]>
Copilot-Session: 35281c30-3d08-4f05-8c84-2ce4711023d5

* format source

---------

Co-authored-by: Ben Hillis <[email protected]>
Co-authored-by: Copilot <[email protected]>
Copilot-Session: 35281c30-3d08-4f05-8c84-2ce4711023d5
(cherry picked from commit f2d87e0)
@benhillis
Ben Hillis (benhillis) force-pushed the backport-security-fixes-release-2.7 branch from cfb3af6 to c2b1077 Compare September 8, 2026 17:27
Copilot AI review requested due to automatic review settings September 8, 2026 17:27
@benhillis Ben Hillis (benhillis) changed the title [release/2.7] Backport additional security fixes [release/2.7] Backport additional fixes Sep 8, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The backported changes are small, targeted, and align with the stated fixes (bounds/termination validation, loopback binding, and runtime servicing update).

Review details
  • Files reviewed: 6/6 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

Disable service before stopping service during uninstall.

(cherry picked from commit c28bd15)
Copilot AI review requested due to automatic review settings September 8, 2026 19:15

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The rollback path currently forces WSLService to auto-start rather than restoring the pre-uninstall start type, undermining the stated rollback behavior and potentially altering user/system configuration.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Review details
  • Files reviewed: 9/9 changed files
  • Comments generated: 2
  • Review effort level: Lite

Comment thread msipackage/package.wix.in
Comment thread src/windows/wslinstall/DllMain.cpp
@benhillis
Ben Hillis (benhillis) merged commit 6f37bc8 into release/2.7 Sep 10, 2026
8 checks passed
@benhillis
Ben Hillis (benhillis) deleted the backport-security-fixes-release-2.7 branch September 10, 2026 00:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

WSL 2.7.12 → 2.7.13 automatic MSI upgrade leaves runtime VHDs pending deletion; ERROR_FILE_NOT_FOUND after reboot

5 participants