[PATCH nf 1/1] netfilter: xt_TPROXY: require IPv6 protocol match

[email protected], [email protected], [email protected]
Newsgroups gmane.comp.security.firewalls.netfilter.devel
Message-ID <6ca536c61d358bfb1bdfd20aafe3cc16acfd45db.1786968834.git.zhilinz@nebusec.ai>
From: Zhiling Zou <[email protected]>

tproxy_tg6_check() verifies the protocol field value but does not
require IP6T_F_PROTO. A crafted ip6tables rule can set the field to
TCP or UDP while leaving the protocol matching flag clear.

ip6_packet_match() treats such a rule as protocol agnostic and can
invoke tproxy_tg6_v1() for ICMPv6. nf_tproxy_get_sock_v6() warns for
protocols other than TCP and UDP.

Reject rules without IP6T_F_PROTO so TPROXY is invoked only for the
protocols it supports.

Fixes: 6ad7889327a5e ("tproxy: added IPv6 support to the TPROXY target")
Cc: [email protected]
Reported-by: Vega <[email protected]>
Signed-off-by: Zhiling Zou <[email protected]>
---
 net/netfilter/xt_TPROXY.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/net/netfilter/xt_TPROXY.c b/net/netfilter/xt_TPROXY.c
index 5f60e7298a1ea..13a94c9d06c0f 100644
--- a/net/netfilter/xt_TPROXY.c
+++ b/net/netfilter/xt_TPROXY.c
@@ -179,7 +179,8 @@ static int tproxy_tg6_check(const struct xt_tgchk_param *par)
 	if (err)
 		return err;
 
-	if ((i->proto == IPPROTO_TCP || i->proto == IPPROTO_UDP) &&
+	if ((i->flags & IP6T_F_PROTO) &&
+	    (i->proto == IPPROTO_TCP || i->proto == IPPROTO_UDP) &&
 	    !(i->invflags & IP6T_INV_PROTO))
 		return 0;
 
-- 
2.43.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.