[PATCH] netfilter: conntrack_amanda: fix port value truncation

Aamir Ahmed <[email protected]>
Newsgroups gmane.linux.network,gmane.comp.security.firewalls.netfilter.devel,gmane.linux.kernel,gmane.linux.kernel.stable
Message-ID <AS8P251MB0001CCFE2A0F40637E5A366CC8B32@AS8P251MB0001.EURP251.PROD.OUTLOOK.COM>
amanda_help() uses simple_strtoul() to parse the port number from
Amanda CONNECT replies, passing the result directly through htons()
into a __be16.  simple_strtoul() returns unsigned long, so values
above 65535 are silently truncated by the implicit conversion to u16
inside htons().

The existing check "port == 0 || len > 5" is insufficient: it
catches values that truncate to zero (e.g. 65536) and strings longer
than 5 digits, but misses values 65537-99999 whose u16 truncation is
non-zero.  For example, port 65537 becomes port 1, creating a
conntrack expectation for an unintended port.

Parse into an unsigned long and explicitly reject values above 65535
before the htons() conversion, mirroring the pattern used by the FTP
helper's get_port() and the recent IPVS FTP fix (commit
e625a9477d12).

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Aamir Ahmed <[email protected]>
---
 net/netfilter/nf_conntrack_amanda.c | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/net/netfilter/nf_conntrack_amanda.c b/net/netfilter/nf_conntrack_amanda.c
index 14ae660491f3..057cef7e2a7e 100644
--- a/net/netfilter/nf_conntrack_amanda.c
+++ b/net/netfilter/nf_conntrack_amanda.c
@@ -91,6 +91,7 @@ static int amanda_help(struct sk_buff *skb,
 	char pbuf[sizeof("65535")], *tmp;
 	u16 len;
 	__be16 port;
+	unsigned long tmp_port;
 	int ret = NF_ACCEPT;
 	nf_nat_amanda_hook_fn *nf_nat_amanda;
 
@@ -132,10 +133,11 @@ static int amanda_help(struct sk_buff *skb,
 			break;
 		pbuf[len] = '\0';
 
-		port = htons(simple_strtoul(pbuf, &tmp, 10));
+		tmp_port = simple_strtoul(pbuf, &tmp, 10);
 		len = tmp - pbuf;
-		if (port == 0 || len > 5)
+		if (tmp_port == 0 || tmp_port > 65535 || len > 5)
 			break;
+		port = htons(tmp_port);
 
 		exp = nf_ct_expect_alloc(ct);
 		if (exp == NULL) {
-- 
2.43.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.