Repository navigation
[release/2.7] Backport additional fixes - #41540
Conversation
…#40402) * Validate NUL-termination of flexible-array Buffer in interop messages Use string::FromMessageBuffer<T>() instead of directly accessing the Buffer[] flexible-array member in interop message structs. FromMessageBuffer validates that a NUL terminator exists within the span bounds, preventing out-of-bounds reads when a malformed message contains no Buffer data or lacks NUL termination. Affected message handlers: - LxInitMessageQueryEnvironmentVariable (config.cpp) - LxInitMessageCreateLoginSession (config.cpp) - LxMiniInitMessageUnmount (main.cpp) Co-authored-by: Copilot <[email protected]> * Remove unused Message parameter name in WSLC_UNMOUNT handler After switching to FromMessageBuffer, the Message parameter is no longer referenced directly. Remove the name to avoid -Wunused-parameter. Co-authored-by: Copilot <[email protected]> --------- Co-authored-by: Ben Hillis <[email protected]> Co-authored-by: Copilot <[email protected]> (cherry picked from commit 909d5eb)
There was a problem hiding this comment.
🔵 Needs a closer look
It backports multiple security-sensitive changes across networking and init message parsing, where subtle behavioral differences on the release branch warrant final human review.
Pull request overview
This PR backports a set of security and defense-in-depth fixes from master to the release/2.7 branch across Linux init message handling, mirrored networking port allocation, KdRelay binding behavior, distribution import parsing, and the bundled .NET runtime.
Changes:
- Harden Linux init interop message parsing by validating NUL-termination for flexible-array
Buffer[]fields viastring::FromMessageBuffer<T>(). - Prevent mirrored-network guest binds to ports in the host ephemeral port range (except where the port is within the guest’s reserved ephemeral range), and add mirrored-mode tests to validate the denial behavior.
- Restrict KdRelay (wslrelay) listener binding to loopback, validate
TerminalProfileSizeagainst the import-result buffer, and update the bundled .NET runtime packages to10.0.11.
File summaries
| File | Description |
|---|---|
| test/windows/NetworkTests.cpp | Adds mirrored-mode tests verifying guest binds into the host ephemeral port range are denied (TCP/UDP). |
| src/windows/wslrelay/main.cpp | Binds the listener to INADDR_LOOPBACK to restrict access to local connections. |
| src/windows/service/exe/WslCoreGuestNetworkService.h | Introduces helpers/state for checking host/guest ephemeral port ranges. |
| src/windows/service/exe/WslCoreGuestNetworkService.cpp | Queries host ephemeral ranges via WMI at startup and denies guest binds into the host range unless within the guest reserved range. |
| src/windows/service/exe/LxssUserSession.cpp | Bounds-checks TerminalProfileSize when slicing the import-result buffer. |
| src/shared/inc/stringshared.h | Adds FromMessageBuffer<T>() wrapper over FromSpan() using offsetof(T, Buffer) for flexible-array buffers. |
| src/linux/init/main.cpp | Uses FromMessageBuffer for unmount message buffer parsing to ensure NUL-terminated access. |
| src/linux/init/config.cpp | Uses FromMessageBuffer for environment-variable query and login-session creation messages to ensure NUL-terminated access. |
| packages.config | Updates Microsoft.NETCore.App.Runtime win-x64/win-arm64 package versions to 10.0.11. |
Review details
- Files reviewed: 9/9 changed files
- Comments generated: 0
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Restrict the KdRelay listener to local connections. Co-authored-by: Copilot <[email protected]> Co-authored-by: Ben Hillis <[email protected]> Copilot-Session: d9d1a097-a7bc-4c1b-806b-d3778adfd23a (cherry picked from commit 5eb2138)
(cherry picked from commit 8edd976)
* Fix unvalidated TerminalProfileSize when importing a distribution _ProcessImportResultMessage constructed the terminal profile string_view using the message-supplied TerminalProfileSize without validating it against the received buffer length. Use the bounds-checked two-argument span::subspan() overload (matching the existing ShortcutIconSize handling a few lines above) so an inconsistent size value throws instead of producing a string_view that runs past the end of the buffer. Co-authored-by: Copilot <[email protected]> Copilot-Session: 35281c30-3d08-4f05-8c84-2ce4711023d5 * format source --------- Co-authored-by: Ben Hillis <[email protected]> Co-authored-by: Copilot <[email protected]> Copilot-Session: 35281c30-3d08-4f05-8c84-2ce4711023d5 (cherry picked from commit f2d87e0)
cfb3af6 to
c2b1077
Compare
There was a problem hiding this comment.
🟢 Approval recommended
The backported changes are small, targeted, and align with the stated fixes (bounds/termination validation, loopback binding, and runtime servicing update).
Review details
- Files reviewed: 6/6 changed files
- Comments generated: 0 new
- Review effort level: Lite
Disable service before stopping service during uninstall. (cherry picked from commit c28bd15)
There was a problem hiding this comment.
🟡 Changes recommended
The rollback path currently forces WSLService to auto-start rather than restoring the pre-uninstall start type, undermining the stated rollback behavior and potentially altering user/system configuration.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Review details
- Files reviewed: 9/9 changed files
- Comments generated: 2
- Review effort level: Lite
Backports the following security and servicing fixes from
mastertorelease/2.7:909d5eb8) Validate NUL termination of flexible-array buffers in Linux init messages.c28bd152) Disable the WSL service before stopping it during uninstall to close the restart race, and restore its start mode on rollback.5eb21381) Restrict KdRelay to the loopback interface.8edd976b) Update the bundled .NET runtime from 10.0.9 to 10.0.11 for the July and August security servicing fixes.f2d87e07) ValidateTerminalProfileSizeagainst the received import-result buffer.Backport adaptations:
release/2.7; the sharedFromMessageBufferhelper is included for the two applicable Linux init handlers.Validation:
cmake --build . --target init wslservice wslrelay wsl wslinstall -- -mwslserviceproxystubunresolvedWSLCCompat_ProxyFileInfo/wslc_ProxyFileInfosymbols on this release checkout.