[PATCH] netfilter: nf_conntrack_h323: fix OOB read in decode_enum()

Aamir Ahmed <[email protected]>
Newsgroups gmane.linux.kernel.stable,gmane.comp.security.firewalls.netfilter.devel,gmane.linux.network
Message-ID <AS8P251MB00011EEAA381DC17852BA37CC8B22@AS8P251MB0001.EURP251.PROD.OUTLOOK.COM>
In decode_enum(), get_bit(bs) is called to read the extension marker
bit without first verifying that the bitstream has enough data
remaining. get_bit() dereferences bs->cur directly:

    unsigned int b = (*bs->cur) & (0x80 >> bs->bit);

When the bitstream is exhausted (bs->cur >= bs->end), this results in a
one-byte out-of-bounds read from the skb data area.

Both decode_seq() and decode_choice() correctly call
nf_h323_error_boundary(bs, 0, 1) before reading the extension bit via
get_bit(). decode_enum() is the only decoder that omits this check.

The bug is reachable when parsing a truncated H.323 message containing a
PER-encoded enumeration with the extension marker (such as the
screeningIndicator field), through port 1720 with the nf_conntrack_h323
helper active.

Add the missing nf_h323_error_boundary(bs, 0, 1) check before get_bit()
to match the pattern used in decode_seq() and decode_choice().

Fixes: 5e35941d9901 ("[NETFILTER]: Add H.323 conntrack/NAT helper")
Cc: [email protected]
Signed-off-by: Aamir Ahmed <[email protected]>
---
 net/netfilter/nf_conntrack_h323_asn1.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/net/netfilter/nf_conntrack_h323_asn1.c b/net/netfilter/nf_conntrack_h323_asn1.c
index 6830c9da3507..ba6ce1f04e1e 100644
--- a/net/netfilter/nf_conntrack_h323_asn1.c
+++ b/net/netfilter/nf_conntrack_h323_asn1.c
@@ -363,6 +363,8 @@ static int decode_enum(struct bitstr *bs, const struct field_t *f,
 {
 	PRINT("%*s%s\n", level * TAB_SIZE, " ", f->name);
 
+	if (nf_h323_error_boundary(bs, 0, 1))
+		return H323_ERROR_BOUND;
 	if ((f->attr & EXT) && get_bit(bs)) {
 		INC_BITS(bs, 7);
 	} else {
-- 
2.43.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.