[PATCH xserver] Fix OOB access in ProcRecordUnregisterClients

Adam Jackson ajax at nwnk.net
Mon Mar 20 20:20:50 UTC 2017

On Sun, 2017-03-19 at 17:55 +0100, Tobias Stoeckmann wrote:
> If a client sends a RecordUnregisterClients request with an nClients
> field larger than INT_MAX / 4, an integer overflow leads to an
> out of boundary access in RecordSanityCheckClientSpecifiers.
> An example line with libXtst would be:
> XRecordUnregisterClients(dpy, rc, clients, 0x40000001);


