Netdev List
 help / color / mirror / Atom feed
* [PATCH nf-next v2] netfilter: nf_conntrack_sip: only honour Via: port in original direction
@ 2026-10-08 15:28 Joas Antonio dos Santos
  0 siblings, 0 replies; only message in thread
From: Joas Antonio dos Santos @ 2026-10-08 15:28 UTC (permalink / raw)
  To: Pablo Neira Ayuso, Florian Westphal
  Cc: Phil Sutter, netfilter-devel, coreteam, netdev

The Cisco phone workaround in process_sip_request() records the port
from the topmost Via: header in ct_sip_info->forced_dport whenever the
Via address matches the sender of the current request and the port
differs from the sender's source port.  nf_nat_sip() then rewrites the
UDP destination port of every reply-direction packet to that value.

The workaround is meant for phones behind the NAT, i.e. requests in the
original direction, but the check is done in both directions.  For a
request arriving in the reply direction, ct->tuplehash[dir].tuple.src
is the remote peer itself, so the peer meets the condition with a Via:
line carrying its own address and any port >= 1024.  From then on its
datagrams on that flow are delivered to the NATed host on the port it
chose rather than the mapped one.  No spoofing is needed, but the peer
has to be the SIP server or proxy the client talks to, and the effect
is limited to that flow.

Only honour the Via: port for requests in the original direction.

Found by manual inspection of nf_conntrack_sip.c and nf_nat_sip.c,
assisted by an LLM, and confirmed at runtime with client, router and
server network namespaces (nft masquerade plus a "sip" ct helper on the
router): the server's request and a following UDP payload reached the
client on the Via: port before this change, and the mapped port after.

Fixes: 7266507d8999 ("netfilter: nf_ct_sip: support Cisco 7941/7945 IP phones")
Signed-off-by: Joas Antonio dos Santos <joasantonio108@gmail.com>
Assisted-by: Claude:claude-opus-5-5
---
Changes in v2:
- Retarget to nf-next as a correctness fix (Pablo).
- Describe the precondition (rogue SIP peer, no spoofing) and how the
  issue was found in the commit message.

 net/netfilter/nf_conntrack_sip.c | 8 +++++++-
 1 file changed, 7 insertions(+), 1 deletion(-)

diff --git a/net/netfilter/nf_conntrack_sip.c b/net/netfilter/nf_conntrack_sip.c
index 64bc440b1..ef655a0bb 100644
--- a/net/netfilter/nf_conntrack_sip.c
+++ b/net/netfilter/nf_conntrack_sip.c
@@ -1586,8 +1586,14 @@ static int process_sip_request(struct sk_buff *skb, unsigned int protoff,
 	 * router for one of these phones, save the port number from the
 	 * Via: header so that nf_nat_sip can redirect the responses to
 	 * the correct port.
+	 *
+	 * Only honour the Via: port for requests coming from the phone,
+	 * i.e. in the original direction.  The remote peer must not be
+	 * able to pick the destination port of packets delivered to the
+	 * NATed host.
 	 */
-	if (ct_sip_parse_header_uri(ct, *dptr, NULL, *datalen,
+	if (dir == IP_CT_DIR_ORIGINAL &&
+	    ct_sip_parse_header_uri(ct, *dptr, NULL, *datalen,
 				    SIP_HDR_VIA_UDP, NULL, &matchoff,
 				    &matchlen, &addr, &port) > 0 &&
 	    port != ct->tuplehash[dir].tuple.src.u.udp.port &&

^ permalink raw reply related	[flat|nested] only message in thread

only message in thread, other threads:[~2026-10-08 15:28 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-08 15:28 [PATCH nf-next v2] netfilter: nf_conntrack_sip: only honour Via: port in original direction Joas Antonio dos Santos

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox