Hello,On Thu, 13 Aug 2026, Joas Antonio wrote: > From: Joas Antonio dos Santos <[email protected]> > > ip_vs_ftp_get_addrport() accumulates decimal digits into a __u16 > (hport) and into unsigned char (p[]) without checking for overflow. > A crafted FTP PASV/EPSV response with an over-long port or address > octet wraps the value, so the helper configures the data connection > with a truncated port/address. > > The netfilter conntrack FTP helper had the same defect, fixed in > commit 2b413fc689ba ("netfilter: nf_conntrack_ftp: avoid u16 > overflows"). Apply the equivalent fix here: widen the port accumulator > to u32 and reject values above 65535, and reject address octets above > 255. > > Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") > Signed-off-by: Joas Antonio dos Santos <[email protected]> Looks good to me for the nf tree, thanks! Acked-by: Julian Anastasov <[email protected]> > --- > v2: use real name in Signed-off-by, add subsystem tag to subject (per > Pablo Neira Ayuso) > > net/netfilter/ipvs/ip_vs_ftp.c | 10 ++++++++-- > 1 file changed, 8 insertions(+), 2 deletions(-) > > diff --git a/net/netfilter/ipvs/ip_vs_ftp.c b/net/netfilter/ipvs/ip_vs_ftp.c > index b315c608f..9e3e005a8 100644 > --- a/net/netfilter/ipvs/ip_vs_ftp.c > +++ b/net/netfilter/ipvs/ip_vs_ftp.c > @@ -102,7 +102,7 @@ static int ip_vs_ftp_get_addrport(char *data, char > *data_limit, > char *s, c; > unsigned char p[6]; > char edelim; > - __u16 hport; > + __u32 hport; > int i = 0; > > if (data_limit - data < plen) { > @@ -144,7 +144,11 @@ static int ip_vs_ftp_get_addrport(char *data, char > *data_limit, > return -1; > c = *data; > if (isdigit(c)) { > - p[i] = p[i]*10 + c - '0'; > + unsigned int val = p[i] * 10 + c - '0'; > + > + if (val > 255) > + return -1; > + p[i] = val; > } else if (c == ',' && i < 5) { > i++; > p[i] = 0; > @@ -222,6 +226,8 @@ static int ip_vs_ftp_get_addrport(char *data, char > *data_limit, > if (!isdigit(*s)) > break; > hport = hport * 10 + *s - '0'; > + if (hport > 65535) > + return -1; > } > if (s == data_limit || !hport || *s != edelim) > return -1; > -- > 2.39.5 (Apple Git-154) Regards -- Julian Anastasov <[email protected]>

