netfilter: nft_exthdr: Search chunks in SCTP packets only
authorPhil Sutter <phil@nwl.cc>
Fri, 11 Jun 2021 17:06:45 +0000 (19:06 +0200)
committerPablo Neira Ayuso <pablo@netfilter.org>
Wed, 16 Jun 2021 20:25:01 +0000 (22:25 +0200)
Since user space does not generate a payload dependency, plain sctp
chunk matches cause searching in non-SCTP packets, too. Avoid this
potential mis-interpretation of packet data by checking pkt->tprot.

Fixes: 133dc203d77df ("netfilter: nft_exthdr: Support SCTP chunks")
Signed-off-by: Phil Sutter <phil@nwl.cc>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
net/netfilter/nft_exthdr.c

index 7f705b5..9cf86be 100644 (file)
@@ -312,6 +312,9 @@ static void nft_exthdr_sctp_eval(const struct nft_expr *expr,
        const struct sctp_chunkhdr *sch;
        struct sctp_chunkhdr _sch;
 
+       if (pkt->tprot != IPPROTO_SCTP)
+               goto err;
+
        do {
                sch = skb_header_pointer(pkt->skb, offset, sizeof(_sch), &_sch);
                if (!sch || !sch->length)
@@ -334,7 +337,7 @@ static void nft_exthdr_sctp_eval(const struct nft_expr *expr,
                }
                offset += SCTP_PAD4(ntohs(sch->length));
        } while (offset < pkt->skb->len);
-
+err:
        if (priv->flags & NFT_EXTHDR_F_PRESENT)
                nft_reg_store8(dest, false);
        else