From: Rahul Chandelkar <rc@rexion.ai>
To: Pablo Neira Ayuso <pablo@netfilter.org>
Cc: Jozsef Kadlecsik <kadlec@netfilter.org>,
Florian Westphal <fw@strlen.de>, Phil Sutter <phil@nwl.cc>,
netfilter-devel@vger.kernel.org, coreteam@netfilter.org,
davem@davemloft.net, edumazet@google.com, kuba@kernel.org,
pabeni@redhat.com, netdev@vger.kernel.org,
Rahul Chandelkar <rc@rexion.ai>,
Sashiko <netdev-bot+sashiko@kernel.org>
Subject: [PATCH nf-next v5 3/4] netfilter: nf_conntrack_amanda: use nf_ct_helper_parse_port()
Date: Mon, 28 Sep 2026 19:44:03 +0000 [thread overview]
Message-ID: <41754da04debbc9e82c77549e1cfc5171ae0f365.1790596690.git.rc@rexion.ai> (raw)
In-Reply-To: <cover.1790596690.git.rc@rexion.ai>
amanda_help() passes the result of simple_strtoul() straight through
htons() into a __be16, so values 65536-99999 are truncated (e.g. 65537
becomes 1). In addition, the port field is copied into a buffer that
only holds five digits, so a longer field such as 123456 is cut down to
12345 and accepted as a different port, and on the NAT path only its
first five bytes are mangled. Either way a conntrack expectation is
created for a port that never appeared in the reply.
Make pbuf one byte larger so that a sixth digit is copied, and use
nf_ct_helper_parse_port(), which rejects port 0, values above 65535 and
digit runs longer than five characters. The trailing len is still
derived from the parser's end pointer for the NAT mangle path.
Build-tested with allmodconfig and allyesconfig (W=1) and sparse, and
cross-built for i386 and big-endian powerpc. The parser
was also checked in a userspace harness; the change has not been
run-time tested with Amanda traffic.
Fixes: 16958900578b ("[NETFILTER]: nf_conntrack/nf_nat: add amanda helper port")
Reported-by: Sashiko <netdev-bot+sashiko@kernel.org>
Closes: https://lore.kernel.org/all/179053062399.2160803.9591526412956900613@kernel.org/
Assisted-by: Claude-Code:claude-opus-5-5 sparse
Signed-off-by: Rahul Chandelkar <rc@rexion.ai>
---
net/netfilter/nf_conntrack_amanda.c | 13 +++++++++----
1 file changed, 9 insertions(+), 4 deletions(-)
diff --git a/net/netfilter/nf_conntrack_amanda.c b/net/netfilter/nf_conntrack_amanda.c
index 14ae660491f3..a9c1ef1ee415 100644
--- a/net/netfilter/nf_conntrack_amanda.c
+++ b/net/netfilter/nf_conntrack_amanda.c
@@ -88,7 +88,8 @@ static int amanda_help(struct sk_buff *skb,
struct nf_conntrack_expect *exp;
struct nf_conntrack_tuple *tuple;
unsigned int dataoff, start, stop, off, i;
- char pbuf[sizeof("65535")], *tmp;
+ char pbuf[sizeof("65535") + 1], *tmp;
+ u16 parsed_port;
u16 len;
__be16 port;
int ret = NF_ACCEPT;
@@ -127,15 +128,19 @@ static int amanda_help(struct sk_buff *skb,
continue;
off += start + search[i].len;
+ /*
+ * pbuf holds one byte more than the longest port so that
+ * an over-long digit run is seen and rejected.
+ */
len = min_t(unsigned int, sizeof(pbuf) - 1, stop - off);
if (skb_copy_bits(skb, off, pbuf, len))
break;
pbuf[len] = '\0';
- port = htons(simple_strtoul(pbuf, &tmp, 10));
- len = tmp - pbuf;
- if (port == 0 || len > 5)
+ if (nf_ct_helper_parse_port(pbuf, len, &parsed_port, &tmp))
break;
+ port = htons(parsed_port);
+ len = tmp - pbuf;
exp = nf_ct_expect_alloc(ct);
if (exp == NULL) {
--
2.43.0
next prev parent reply other threads:[~2026-09-28 19:44 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-28 16:28 [PATCH nf-next v5 0/4] netfilter: conntrack: shared port parser for helpers Rahul Chandelkar
2026-09-28 17:33 ` [PATCH nf-next v5 1/4] netfilter: conntrack: add shared uint and port parsers " Rahul Chandelkar
2026-09-28 18:39 ` [PATCH nf-next v5 2/4] netfilter: nf_conntrack_irc: use nf_ct_helper_parse_port() Rahul Chandelkar
2026-09-28 19:44 ` Rahul Chandelkar [this message]
2026-09-28 20:49 ` [PATCH nf-next v5 4/4] netfilter: nf_conntrack_sip: use shared helper parsers Rahul Chandelkar
2026-09-28 20:56 ` [PATCH nf-next v5 0/4] netfilter: conntrack: shared port parser for helpers netdev-bot+sinfo
2026-09-30 9:57 ` Rahul Chandelkar
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=41754da04debbc9e82c77549e1cfc5171ae0f365.1790596690.git.rc@rexion.ai \
--to=rc@rexion.ai \
--cc=coreteam@netfilter.org \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=fw@strlen.de \
--cc=kadlec@netfilter.org \
--cc=kuba@kernel.org \
--cc=netdev-bot+sashiko@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=netfilter-devel@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=pablo@netfilter.org \
--cc=phil@nwl.cc \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox