Patch "netfilter: nft_exthdr: Search chunks in SCTP packets only" has been added to the 5.10-stable tree

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



This is a note to let you know that I've just added the patch titled

    netfilter: nft_exthdr: Search chunks in SCTP packets only

to the 5.10-stable tree which can be found at:
    http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary

The filename of the patch is:
     netfilter-nft_exthdr-search-chunks-in-sctp-packets-o.patch
and it can be found in the queue-5.10 subdirectory.

If you, or anyone else, feels it should not be added to the stable tree,
please let <stable@xxxxxxxxxxxxxxx> know about it.



commit 1342f4dc576095f01825d0670c5561884bd23845
Author: Phil Sutter <phil@xxxxxx>
Date:   Fri Jun 11 19:06:45 2021 +0200

    netfilter: nft_exthdr: Search chunks in SCTP packets only
    
    [ Upstream commit 5acc44f39458f43dac9724cefa4da29847cfe997 ]
    
    Since user space does not generate a payload dependency, plain sctp
    chunk matches cause searching in non-SCTP packets, too. Avoid this
    potential mis-interpretation of packet data by checking pkt->tprot.
    
    Fixes: 133dc203d77df ("netfilter: nft_exthdr: Support SCTP chunks")
    Signed-off-by: Phil Sutter <phil@xxxxxx>
    Signed-off-by: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
    Signed-off-by: Sasha Levin <sashal@xxxxxxxxxx>

diff --git a/net/netfilter/nft_exthdr.c b/net/netfilter/nft_exthdr.c
index b4682aeabab96..274c5f0085186 100644
--- a/net/netfilter/nft_exthdr.c
+++ b/net/netfilter/nft_exthdr.c
@@ -371,6 +371,9 @@ static void nft_exthdr_sctp_eval(const struct nft_expr *expr,
 	const struct sctp_chunkhdr *sch;
 	struct sctp_chunkhdr _sch;
 
+	if (pkt->tprot != IPPROTO_SCTP)
+		goto err;
+
 	do {
 		sch = skb_header_pointer(pkt->skb, offset, sizeof(_sch), &_sch);
 		if (!sch || !sch->length)
@@ -391,7 +394,7 @@ static void nft_exthdr_sctp_eval(const struct nft_expr *expr,
 		}
 		offset += SCTP_PAD4(ntohs(sch->length));
 	} while (offset < pkt->skb->len);
-
+err:
 	if (priv->flags & NFT_EXTHDR_F_PRESENT)
 		nft_reg_store8(dest, false);
 	else



[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Index of Archives]     [Linux USB Devel]     [Linux Audio Users]     [Yosemite News]     [Linux Kernel]     [Linux SCSI]

  Powered by Linux