Thread (15 messages) 15 messages, 4 authors, 2020-09-01

Re: [PATCH 1/1] netfilter: nat: add range checks for access to nf_nat_l[34]protos[]

From: Pablo Neira Ayuso <pablo@netfilter.org>
Date: 2020-07-31 17:51:21
Also in: lkml, netfilter-devel

Hi William,

On Fri, Jul 31, 2020 at 12:26:11AM +0000, William Mcvicker wrote:
Hi Pablo,

Yes, I believe this oops is only triggered by userspace when the user
specifically passes in an invalid nf_nat_l3protos index. I'm happy to re-work
the patch to check for this in ctnetlink_create_conntrack().
Great.

Note that this code does not exist in the tree anymore. I'm not sure
if this problem still exists upstream, this patch does not apply to
nf.git. This fix should only go for -stable maintainers.
quoted
BTW, do you have a Fixes: tag for this? This will be useful for
-stable maintainer to pick up this fix.
Regarding the Fixes: tag, I don't have one offhand since this bug was reported
to me, but I can search through the code history to find the commit that
exposed this vulnerability.
That would be great.

Thank you.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help