Thread (5 messages) 5 messages, 2 authors, 5d ago

Re: [PATCH net 0/2] netfilter: nf_conntrack_h323: fixes for NAT bypass and ASN.1 decode

From: Subham Pal <hidden>
Date: 2026-09-23 10:47:05
Also in: netfilter-devel, stable

On Wed, Sep 23, 2026 at 2:16 PM Pablo Neira Ayuso [off-list ref] wrote:
I understand these are correctness fixes.
Do you have a reproducer/PoC? Do you tests for this?
Hi Pablo,

Both issues were found while testing a netfilter based linux
firewall with communicating devices from multiple vendors
(Panasonic, PeopleLink, YeaLink and Plycom).

1. For patch 1 (NAT expectation bypass)
- Environment & Setup
  Linux firewall performing NAT between internal and external
  network segment with Panasonic, PeopleLink, YeaLink
  and Polycom endpoints.
- Observation
  Call setup failing due to missing conntrack expectation from
  initial Q.931.

2. For patch 2 (Failed ASN.1 parsing)
- Environment & Setup
  The same setup but this problem happened particularly with
  Panasonic endpoint.
- Observation
  Panasonic endpoint advertises sequence extension with missing
  optional fields during call setup. Due to misaligned check for presence
  of field, I was getting H323_ERROR_BOUND error in dmesg.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help