Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 37e55cf0 authored by Jan Engelhardt's avatar Jan Engelhardt Committed by Patrick McHardy
Browse files

netfilter: xt_recent: fix stack overread in compat code



Related-to: commit 325fb5b4

The compat path suffers from a similar problem. It only uses a __be32
when all of the recent code uses, and expects, an nf_inet_addr
everywhere. As a result, addresses stored by xt_recents were
filled with whatever other stuff was on the stack following the be32.

Signed-off-by: default avatarJan Engelhardt <jengelh@medozas.de>

With a minor compile fix from Roman.

Reported-and-tested-by: default avatarRoman Hoog Antink <rha@open.ch>
Signed-off-by: default avatarPatrick McHardy <kaber@trash.net>
parent 71951b64
Loading
Loading
Loading
Loading
+4 −5
Original line number Diff line number Diff line
@@ -474,7 +474,7 @@ static ssize_t recent_old_proc_write(struct file *file,
	struct recent_table *t = pde->data;
	struct recent_entry *e;
	char buf[sizeof("+255.255.255.255")], *c = buf;
	__be32 addr;
	union nf_inet_addr addr = {};
	int add;

	if (size > sizeof(buf))
@@ -506,14 +506,13 @@ static ssize_t recent_old_proc_write(struct file *file,
		add = 1;
		break;
	}
	addr = in_aton(c);
	addr.ip = in_aton(c);

	spin_lock_bh(&recent_lock);
	e = recent_entry_lookup(t, (const void *)&addr, NFPROTO_IPV4, 0);
	e = recent_entry_lookup(t, &addr, NFPROTO_IPV4, 0);
	if (e == NULL) {
		if (add)
			recent_entry_init(t, (const void *)&addr,
					  NFPROTO_IPV4, 0);
			recent_entry_init(t, &addr, NFPROTO_IPV4, 0);
	} else {
		if (add)
			recent_entry_update(t, e);