[PATCH 2/3] netfilter: potential null derefence.

Subsystems: ethernet bridge, networking [general], the rest

STALE5308d

7 messages, 3 authors, 2012-03-03 · open the first message on its own page

[PATCH 2/3] netfilter: potential null derefence.

From: santosh nayak <hidden>
Date: 2012-03-01 09:24:38

From: Santosh Nayak <redacted>

I am getting following error.
" net/bridge/netfilter/ebtables.c:269 ebt_do_table()
  error: potential null derefence 'cs'"

    i = cs[sp].n;  // If cs == Null then this will cause problem.

Signed-off-by: Santosh Nayak <redacted>
---
 net/bridge/netfilter/ebtables.c |    5 ++++-
 1 files changed, 4 insertions(+), 1 deletions(-)
diff --git a/net/bridge/netfilter/ebtables.c b/net/bridge/netfilter/ebtables.c
index f3fcbd9..9c0f177 100644
--- a/net/bridge/netfilter/ebtables.c
+++ b/net/bridge/netfilter/ebtables.c
@@ -209,8 +209,10 @@ unsigned int ebt_do_table (unsigned int hook, struct sk_buff *skb,
 	   smp_processor_id());
 	if (private->chainstack)
 		cs = private->chainstack[smp_processor_id()];
-	else
+	else {
 		cs = NULL;
+		goto out;
+	}
 	chaininfo = private->hook_entry[hook];
 	nentries = private->hook_entry[hook]->nentries;
 	point = (struct ebt_entry *)(private->hook_entry[hook]->data);
@@ -313,6 +315,7 @@ letscontinue:
 		read_unlock_bh(&table->lock);
 		return NF_ACCEPT;
 	}
+out:
 	read_unlock_bh(&table->lock);
 	return NF_DROP;
 }
-- 
1.7.4.4

Re: [PATCH 2/3] netfilter: potential null derefence.

From: Pablo Neira Ayuso <pablo@netfilter.org>
Date: 2012-03-01 10:21:41

On Thu, Mar 01, 2012 at 02:47:14PM +0530, santosh nayak wrote:
quoted hunk
From: Santosh Nayak <redacted>

I am getting following error.
" net/bridge/netfilter/ebtables.c:269 ebt_do_table()
  error: potential null derefence 'cs'"

    i = cs[sp].n;  // If cs == Null then this will cause problem.

Signed-off-by: Santosh Nayak <redacted>
---
 net/bridge/netfilter/ebtables.c |    5 ++++-
 1 files changed, 4 insertions(+), 1 deletions(-)
diff --git a/net/bridge/netfilter/ebtables.c b/net/bridge/netfilter/ebtables.c
index f3fcbd9..9c0f177 100644
--- a/net/bridge/netfilter/ebtables.c
+++ b/net/bridge/netfilter/ebtables.c
@@ -209,8 +209,10 @@ unsigned int ebt_do_table (unsigned int hook, struct sk_buff *skb,
 	   smp_processor_id());
 	if (private->chainstack)
 		cs = private->chainstack[smp_processor_id()];
-	else
+	else {
 		cs = NULL;
+		goto out;
There is no "out" label in ebt_do_table !!

Re: [PATCH 2/3] netfilter: potential null derefence.

From: santosh prasad nayak <hidden>
Date: 2012-03-01 10:23:32

Hi Pablo,

Please look at the last line of my patch.
I have added a new label "out"

regards
santosh

On Thu, Mar 1, 2012 at 3:51 PM, Pablo Neira Ayuso [off-list ref] wrote:
On Thu, Mar 01, 2012 at 02:47:14PM +0530, santosh nayak wrote:
quoted
From: Santosh Nayak <redacted>

I am getting following error.
" net/bridge/netfilter/ebtables.c:269 ebt_do_table()
  error: potential null derefence 'cs'"

    i = cs[sp].n;  // If cs == Null then this will cause problem.

Signed-off-by: Santosh Nayak <redacted>
---
 net/bridge/netfilter/ebtables.c |    5 ++++-
 1 files changed, 4 insertions(+), 1 deletions(-)
diff --git a/net/bridge/netfilter/ebtables.c b/net/bridge/netfilter/ebtables.c
index f3fcbd9..9c0f177 100644
--- a/net/bridge/netfilter/ebtables.c
+++ b/net/bridge/netfilter/ebtables.c
@@ -209,8 +209,10 @@ unsigned int ebt_do_table (unsigned int hook, struct sk_buff *skb,
         smp_processor_id());
      if (private->chainstack)
              cs = private->chainstack[smp_processor_id()];
-     else
+     else {
              cs = NULL;
+             goto out;
There is no "out" label in ebt_do_table !!

Re: [PATCH 2/3] netfilter: potential null derefence.

From: Pablo Neira Ayuso <pablo@netfilter.org>
Date: 2012-03-01 12:30:16

On Thu, Mar 01, 2012 at 02:47:14PM +0530, santosh nayak wrote:
From: Santosh Nayak <redacted>

I am getting following error.
" net/bridge/netfilter/ebtables.c:269 ebt_do_table()
  error: potential null derefence 'cs'"

    i = cs[sp].n;  // If cs == Null then this will cause problem.
Very sorry, I didn't see the out label.

I'll apply this to my nf [1] once David takes my previous request for
pulling.

[1] http://1984.lsi.us.es/git/net

Re: [PATCH 2/3] netfilter: potential null derefence.

From: Pablo Neira Ayuso <pablo@netfilter.org>
Date: 2012-03-02 01:22:15

On Thu, Mar 01, 2012 at 02:47:14PM +0530, santosh nayak wrote:
quoted hunk
From: Santosh Nayak <redacted>

I am getting following error.
" net/bridge/netfilter/ebtables.c:269 ebt_do_table()
  error: potential null derefence 'cs'"

    i = cs[sp].n;  // If cs == Null then this will cause problem.

Signed-off-by: Santosh Nayak <redacted>
---
 net/bridge/netfilter/ebtables.c |    5 ++++-
 1 files changed, 4 insertions(+), 1 deletions(-)
diff --git a/net/bridge/netfilter/ebtables.c b/net/bridge/netfilter/ebtables.c
index f3fcbd9..9c0f177 100644
--- a/net/bridge/netfilter/ebtables.c
+++ b/net/bridge/netfilter/ebtables.c
@@ -209,8 +209,10 @@ unsigned int ebt_do_table (unsigned int hook, struct sk_buff *skb,
 	   smp_processor_id());
 	if (private->chainstack)
 		cs = private->chainstack[smp_processor_id()];
-	else
+	else {
 		cs = NULL;
I just noticed we can remove this cs = NULL. No need to resend, I'll
mangle it myself.
quoted hunk
+		goto out;
+	}
 	chaininfo = private->hook_entry[hook];
 	nentries = private->hook_entry[hook]->nentries;
 	point = (struct ebt_entry *)(private->hook_entry[hook]->data);
@@ -313,6 +315,7 @@ letscontinue:
 		read_unlock_bh(&table->lock);
 		return NF_ACCEPT;
 	}
+out:
 	read_unlock_bh(&table->lock);
 	return NF_DROP;
 }
-- 
1.7.4.4

--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html

Re: [Bridge] [PATCH 2/3] netfilter: potential null derefence.

From: Bart De Schuymer <hidden>
Date: 2012-03-02 21:31:40

Op 1/03/2012 13:30, Pablo Neira Ayuso schreef:
On Thu, Mar 01, 2012 at 02:47:14PM +0530, santosh nayak wrote:
quoted
From: Santosh Nayak<redacted>

I am getting following error.
" net/bridge/netfilter/ebtables.c:269 ebt_do_table()
   error: potential null derefence 'cs'"

     i = cs[sp].n;  // If cs == Null then this will cause problem.
Very sorry, I didn't see the out label.

I'll apply this to my nf [1] once David takes my previous request for
pulling.
Hi,

Has this patch been tested? Really, that code in the core firewall 
function is there for a reason, wouldn't you think?
The chainstack is only allocated when user-defined chains are used (see 
translate_table).
Never blindly trust a tool.

Bart

Re: [Bridge] [PATCH 2/3] netfilter: potential null derefence.

From: Pablo Neira Ayuso <pablo@netfilter.org>
Date: 2012-03-03 09:12:05

On Fri, Mar 02, 2012 at 10:31:23PM +0100, Bart De Schuymer wrote:
Op 1/03/2012 13:30, Pablo Neira Ayuso schreef:
quoted
On Thu, Mar 01, 2012 at 02:47:14PM +0530, santosh nayak wrote:
quoted
From: Santosh Nayak<redacted>

I am getting following error.
" net/bridge/netfilter/ebtables.c:269 ebt_do_table()
  error: potential null derefence 'cs'"

    i = cs[sp].n;  // If cs == Null then this will cause problem.
Very sorry, I didn't see the out label.

I'll apply this to my nf [1] once David takes my previous request for
pulling.
Hi,

Has this patch been tested? Really, that code in the core firewall
function is there for a reason, wouldn't you think?
The chainstack is only allocated when user-defined chains are used
(see translate_table).
Never blindly trust a tool.
I see, then that cs NULL dereference never happens.

Thanks Bart, I'll drop this patch.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help