Re: [PATCH v2 ipvs] ipvs: fix integer overflow in ftp helper port/address parsing

Julian Anastasov <[email protected]>
Newsgroups gmane.comp.security.firewalls.netfilter.devel,gmane.linux.network,gmane.comp.linux.lvs.devel,gmane.linux.kernel
Message-ID <[email protected]>
	Hello,

On Thu, 13 Aug 2026, Joas Antonio wrote:

> From: Joas Antonio dos Santos <[email protected]>
> 
> ip_vs_ftp_get_addrport() accumulates decimal digits into a __u16
> (hport) and into unsigned char (p[]) without checking for overflow.
> A crafted FTP PASV/EPSV response with an over-long port or address
> octet wraps the value, so the helper configures the data connection
> with a truncated port/address.
> 
> The netfilter conntrack FTP helper had the same defect, fixed in
> commit 2b413fc689ba ("netfilter: nf_conntrack_ftp: avoid u16
> overflows"). Apply the equivalent fix here: widen the port accumulator
> to u32 and reject values above 65535, and reject address octets above
> 255.
> 
> Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
> Signed-off-by: Joas Antonio dos Santos <[email protected]>

	Looks good to me for the nf tree, thanks!

Acked-by: Julian Anastasov <[email protected]>

> ---
> v2: use real name in Signed-off-by, add subsystem tag to subject (per
>     Pablo Neira Ayuso)
> 
>  net/netfilter/ipvs/ip_vs_ftp.c | 10 ++++++++--
>  1 file changed, 8 insertions(+), 2 deletions(-)
> 
> diff --git a/net/netfilter/ipvs/ip_vs_ftp.c b/net/netfilter/ipvs/ip_vs_ftp.c
> index b315c608f..9e3e005a8 100644
> --- a/net/netfilter/ipvs/ip_vs_ftp.c
> +++ b/net/netfilter/ipvs/ip_vs_ftp.c
> @@ -102,7 +102,7 @@ static int ip_vs_ftp_get_addrport(char *data, char *data_limit,
>  	char *s, c;
>  	unsigned char p[6];
>  	char edelim;
> -	__u16 hport;
> +	__u32 hport;
>  	int i = 0;
>  
>  	if (data_limit - data < plen) {
> @@ -144,7 +144,11 @@ static int ip_vs_ftp_get_addrport(char *data, char *data_limit,
>  				return -1;
>  			c = *data;
>  			if (isdigit(c)) {
> -				p[i] = p[i]*10 + c - '0';
> +				unsigned int val = p[i] * 10 + c - '0';
> +
> +				if (val > 255)
> +					return -1;
> +				p[i] = val;
>  			} else if (c == ',' && i < 5) {
>  				i++;
>  				p[i] = 0;
> @@ -222,6 +226,8 @@ static int ip_vs_ftp_get_addrport(char *data, char *data_limit,
>  		if (!isdigit(*s))
>  			break;
>  		hport = hport * 10 + *s - '0';
> +		if (hport > 65535)
> +			return -1;
>  	}
>  	if (s == data_limit || !hport || *s != edelim)
>  		return -1;
> -- 
> 2.39.5 (Apple Git-154)

Regards

--
Julian Anastasov <[email protected]>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.