From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from out-zbxj-a75.jellyfish.systems (out-zbxj-a75.jellyfish.systems [198.54.127.75]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 853703E40FB for ; Mon, 28 Sep 2026 19:44:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=198.54.127.75 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790624668; cv=none; b=fZjhWxLVPRTZL0X+bvom65jxn1IQSQA6n9YTeDBb781J8ywpxQXy4kHof/4kfj3n7GICWoSJif5dBtTodTjABDNOABe3OHUy8t9dM+ZQ2ui9FoZyHz4iBcS3PWueQgvulTuZkYgy0EzSAyG68OQViQscAwENDkRMx5iD8yjdwuQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790624668; c=relaxed/simple; bh=8BtFffJxUMZjdKjUyZLZ65tt7JmrPqUPubeAIwEAWXI=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=tKTN10tlu87fiRDm4HSN4sMcjKvoqN0KBlrMxjpUX4b0h+GT4PnA+7btfqyLQM5XDiPSgigQNzjeoGbiCxND9Kg48oAY4URa9alXQ1bGkG5YWKrdX+Ghkqnm9x/N+zYugY+4j5lAZNV/l2OTe1l7Z4eUXxtTfJEc758kEbjcWcc= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=rexion.ai; spf=pass smtp.mailfrom=rexion.ai; dkim=fail (0-bit key) header.d=rexion.ai header.i=@rexion.ai header.b=ZyULdGNJ reason="key not found in DNS"; arc=none smtp.client-ip=198.54.127.75 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=rexion.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=rexion.ai Authentication-Results: smtp.subspace.kernel.org; dkim=fail reason="key not found in DNS" (0-bit key) header.d=rexion.ai header.i=@rexion.ai header.b="ZyULdGNJ" Received: from research-box.ec2.internal (ec2-3-80-226-50.compute-1.amazonaws.com [3.80.226.50]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mail.spacemail.com (Postfix) with ESMTPSA id 4htsFJ2FfDz2x9C; Mon, 28 Sep 2026 19:44:04 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rexion.ai; s=spacemail; t=1790624645; bh=aKwfpfR6D49NNS6/Iw5WZJrvQIJqO5dlq1ymNm9qL/0=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=ZyULdGNJA+4WLNRmPeLHvG6yct6InDJotMb5DbspdJMKkTZGYXtxuwdD4HsyXlWGm g4CFUsWDo0H1dYHK5E5HXMyjAQv9O36IaJ5eNfdaexm5Y5XekdzAE8yvXfLrQwG/du 4niefsgqGUprQhglgCOqCtCX8jrlsnZTUR+b+wJbFEfSTM5YLMzYcjwDEvCrFQAVHC GMrc7OTKgQHRcckfeh/9mgFgSZ0oAZ9IddWNQAIWpecv1HFA6jcjUM3Usm9PMZ+3Gf vNoWvj37UffKCNDseLHOIjaSTvGynTPsUxolzdIG5zeyPdxbXxKHP3eM8sDTfQryeK mWgga3xjyUthg== From: Rahul Chandelkar To: Pablo Neira Ayuso Cc: Jozsef Kadlecsik , Florian Westphal , Phil Sutter , netfilter-devel@vger.kernel.org, coreteam@netfilter.org, davem@davemloft.net, edumazet@google.com, kuba@kernel.org, pabeni@redhat.com, netdev@vger.kernel.org, Rahul Chandelkar , Sashiko Subject: [PATCH nf-next v5 3/4] netfilter: nf_conntrack_amanda: use nf_ct_helper_parse_port() Date: Mon, 28 Sep 2026 19:44:03 +0000 Message-ID: <41754da04debbc9e82c77549e1cfc5171ae0f365.1790596690.git.rc@rexion.ai> X-Mailer: git-send-email 2.43.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: netdev@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Envelope-From: rc@rexion.ai amanda_help() passes the result of simple_strtoul() straight through htons() into a __be16, so values 65536-99999 are truncated (e.g. 65537 becomes 1). In addition, the port field is copied into a buffer that only holds five digits, so a longer field such as 123456 is cut down to 12345 and accepted as a different port, and on the NAT path only its first five bytes are mangled. Either way a conntrack expectation is created for a port that never appeared in the reply. Make pbuf one byte larger so that a sixth digit is copied, and use nf_ct_helper_parse_port(), which rejects port 0, values above 65535 and digit runs longer than five characters. The trailing len is still derived from the parser's end pointer for the NAT mangle path. Build-tested with allmodconfig and allyesconfig (W=1) and sparse, and cross-built for i386 and big-endian powerpc. The parser was also checked in a userspace harness; the change has not been run-time tested with Amanda traffic. Fixes: 16958900578b ("[NETFILTER]: nf_conntrack/nf_nat: add amanda helper port") Reported-by: Sashiko Closes: https://lore.kernel.org/all/179053062399.2160803.9591526412956900613@kernel.org/ Assisted-by: Claude-Code:claude-opus-5-5 sparse Signed-off-by: Rahul Chandelkar --- net/netfilter/nf_conntrack_amanda.c | 13 +++++++++---- 1 file changed, 9 insertions(+), 4 deletions(-) diff --git a/net/netfilter/nf_conntrack_amanda.c b/net/netfilter/nf_conntrack_amanda.c index 14ae660491f3..a9c1ef1ee415 100644 --- a/net/netfilter/nf_conntrack_amanda.c +++ b/net/netfilter/nf_conntrack_amanda.c @@ -88,7 +88,8 @@ static int amanda_help(struct sk_buff *skb, struct nf_conntrack_expect *exp; struct nf_conntrack_tuple *tuple; unsigned int dataoff, start, stop, off, i; - char pbuf[sizeof("65535")], *tmp; + char pbuf[sizeof("65535") + 1], *tmp; + u16 parsed_port; u16 len; __be16 port; int ret = NF_ACCEPT; @@ -127,15 +128,19 @@ static int amanda_help(struct sk_buff *skb, continue; off += start + search[i].len; + /* + * pbuf holds one byte more than the longest port so that + * an over-long digit run is seen and rejected. + */ len = min_t(unsigned int, sizeof(pbuf) - 1, stop - off); if (skb_copy_bits(skb, off, pbuf, len)) break; pbuf[len] = '\0'; - port = htons(simple_strtoul(pbuf, &tmp, 10)); - len = tmp - pbuf; - if (port == 0 || len > 5) + if (nf_ct_helper_parse_port(pbuf, len, &parsed_port, &tmp)) break; + port = htons(parsed_port); + len = tmp - pbuf; exp = nf_ct_expect_alloc(ct); if (exp == NULL) { -- 2.43.0