Page MenuHomeFreeBSD

pf: fix NULL dereference in pfr_set_addrs() with feedback
ClosedPublic

Authored by rcm on Mon, Sep 28, 4:51 PM.

Details

Summary

Since DIOCRSETADDRS was converted to netlink, pf_handle_table_set_addrs()
calls pfr_set_addrs() with a NULL size2, as the netlink interface has no
buffer to return the deleted addresses in. pfr_set_addrs() only checked
size2 for NULL at the end of the function; with PFR_FLAG_FEEDBACK set it
dereferenced it unconditionally first. pfctl sets PFR_FLAG_FEEDBACK
when run with -v, so "pfctl -v -t foo -T replace ..." panicked the
kernel with a NULL pointer dereference. To reproduce:

pfctl -e
pfctl -t foo -T add 192.0.2.1
pfctl -v -t foo -T replace 192.0.2.2

Check size2 for NULL before dereferencing it, as is already done at the
end of the function. The per-address feedback for added and changed
addresses is still copied back as before; only the list of deleted
addresses, which the netlink caller has no room for, is skipped.

While here, compare size2 against NULL explicitly in the second check as
well, per style(9).

Add a regression test.

Fixes: 08ed87a4a276 ("pf: convert DIOCRSETADDRS to netlink")
MFC after: 1 week
Sponsored by: Rubicon Communications, LLC ("Netgate")

Test Plan

Regression test included

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

rcm requested review of this revision.Mon, Sep 28, 4:51 PM
rcm edited the summary of this revision. (Show Details)
This revision was not accepted when it landed; it landed in state Needs Review.Tue, Sep 29, 12:04 AM
This revision was automatically updated to reflect the committed changes.