From nobody Fri Feb 20 02:23:58 2026 X-Original-To: dev-commits-src-branches@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4fHDZl1Md0z6QRfd for ; Fri, 20 Feb 2026 02:23:59 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R12" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4fHDZl0F42z3N18 for ; Fri, 20 Feb 2026 02:23:59 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1771554239; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=WOssPc6kLPiWlI2q5Hc/K1JT08oo6snTrjAODGc2kSQ=; b=XjCPsatxfyVxd6BZNsk5nZ2q25/HVa7JiQ2iZGDcrw7EqE5gRA2cO/BR9sjxGRQjML8BKs Ns5s5vmQRLZ07wcLcdMBZxqdVlJuHt+Mx/ZBGjR/8i+PvTZ6qEkqkAAip0/H/+Zti/D54K +hZB4FIZBS8Bd7jZB8KweVDaTNAVAMCUBxyqmI2IB9GQKBqJ0DKss4rc//GVNZxEvRW9KE h+LIsL4MLm4dqBGzH7AVdKg7ltp4lpr/VYTUKpF7hM7qAHXVIKomULvvbyq1+aiJY6z6zS 3aRKruAphHdMzHy/F/oDIXwtMSTbKuhe+4Bc3SnJlajC/k8L2SakInns67PY/w== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1771554239; a=rsa-sha256; cv=none; b=dSWn1ETRhCDj+zmd0LpsMctTjntFsTdoEsbfSBvwcCgRxEEM8Ixr/5NAfPQVTHcHOUpHAC Of8xenUc0l3/xFlIrhQ+manE2ynDYyLiRUODXX+dQtnQ5+6taWiCbxED+IUBZR81aXmJ+q GTN4Kmi25YByGQyf0IfQePVAnBSICF602VUOn5FUELORYe5OHCH5r7htWcLJCEF+B5jxJ1 W/RAfhUIgX2zxGmgAAENdXjy6Bj49npo7DsL7Ld6mfuDv0EHkducs3jzcqCTfjyYJ5LrDp Jii2srO1Kvjypr8nooCXGqcbaz/GC8djvGZIn8b5ihWVAYEwaIQ6Oz5vsKWM3Q== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1771554239; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=WOssPc6kLPiWlI2q5Hc/K1JT08oo6snTrjAODGc2kSQ=; b=pz74G+H0eKTVDRga82NUGzfbmKY59rth4Xyg21GBCTQoawPptk/p34udLmIhIgJDA2yebW ogvWivrFF7uTWt4ozDKDh3OfQ9HsD150pHv7nTbbf3uH303V+VzvG75ALFMqOfbUaWrxOa krLRkHHWkB53qaCx1WUWggasyIZAwl6maC8IZjJ4UeRWz745fmV4J9XckFKwlbuS8kosHW gBnbW2x9epcM+Dx0g8iodeC3B6VexHg/cbRrCgbreRTkJSOPQ7HChOK5s9xDhC3ZFfOSmh HL9YvqyDXXFyIS45I/fC1WUi4+VG2+tcojQz+/upd/qoH5jboFhy5hy/O9vA9g== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4fHDZk6rV6z17dF for ; Fri, 20 Feb 2026 02:23:58 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 19463 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Fri, 20 Feb 2026 02:23:58 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org From: Cy Schubert Subject: git: afaf984ae0dc - stable/15 - ipfilter: Interface name must not extend beyond end of buffer List-Id: Commits to the stable branches of the FreeBSD src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-branches List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-branches@freebsd.org Sender: owner-dev-commits-src-branches@FreeBSD.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: cy X-Git-Repository: src X-Git-Refname: refs/heads/stable/15 X-Git-Reftype: branch X-Git-Commit: afaf984ae0dc65fce9df561d6d3543addf53adde Auto-Submitted: auto-generated Date: Fri, 20 Feb 2026 02:23:58 +0000 Message-Id: <6997c5be.19463.3e3c0b41@gitrepo.freebsd.org> The branch stable/15 has been updated by cy: URL: https://cgit.FreeBSD.org/src/commit/?id=afaf984ae0dc65fce9df561d6d3543addf53adde commit afaf984ae0dc65fce9df561d6d3543addf53adde Author: Cy Schubert AuthorDate: 2026-01-08 17:41:53 +0000 Commit: Cy Schubert CommitDate: 2026-02-20 02:23:44 +0000 ipfilter: Interface name must not extend beyond end of buffer sifpidx (an interface name) cannot extend beyond the end of the fr_names buffer. We do the validation for fr_sifpidx here because it is a union that contains an offset only when fr_sifpidx points to an interface name, an offset into fr_names. The union is an offset into fr_names in this case only. interr_tbl now becomes a static variable outside a function to facilitate its use by two functions within fil.c Note that sifpidx is only used in ipf_sync() which implments ipf -y. Reported by: Ilja Van Sprundel MFC after: 1 week (cherry picked from commit 47fb51847fdea3f1cce841b5f2bbbcd6f8a04ee0) --- sys/netpfil/ipfilter/netinet/fil.c | 23 +++++++++++++++++++++-- 1 file changed, 21 insertions(+), 2 deletions(-) diff --git a/sys/netpfil/ipfilter/netinet/fil.c b/sys/netpfil/ipfilter/netinet/fil.c index 355c633d59d8..09640623fdf2 100644 --- a/sys/netpfil/ipfilter/netinet/fil.c +++ b/sys/netpfil/ipfilter/netinet/fil.c @@ -236,6 +236,11 @@ static const struct optlist secopt[] = { { IPSO_CLASS_RES1, 0x80 } }; +/* + * Internal errors set by ipf_check_names_string(). + */ +static const int interr_tbl[3] = { 152, 156, 153 }; + char ipfilter_version[] = IPL_VERSION; int ipf_features = 0 @@ -3906,7 +3911,7 @@ ipf_synclist(ipf_main_softc_t *softc, frentry_t *fr, void *ifp) frentry_t *frt, *start = fr; frdest_t *fdp; char *name; - int error; + int error, interr; void *ifa; int v, i; @@ -3933,6 +3938,21 @@ ipf_synclist(ipf_main_softc_t *softc, frentry_t *fr, void *ifp) } if ((fr->fr_type & ~FR_T_BUILTIN) == FR_T_IPF) { + /* + * We do the validation for fr_sifpidx here because + * it is a union that contains an offset only when + * fr_sifpidx points to an interface name, an offset + * into fr_names. The union is an offset into + * fr_names in this case only. + * + * Note that sifpidx is only used in ipf_sync() which + * implments ipf -y. + */ + if ((interr = ipf_check_names_string(fr->fr_names, fr->fr_namelen, fr->fr_sifpidx)) != 0) { + IPFERROR(interr_tbl[interr-1]); + error = EINVAL; + goto unwind; + } if (fr->fr_satype != FRI_NORMAL && fr->fr_satype != FRI_LOOKUP) { ifa = ipf_resolvenic(softc, fr->fr_names + @@ -4404,7 +4424,6 @@ frrequest(ipf_main_softc_t *softc, int unit, ioctlcmd_t req, caddr_t data, int set, int makecopy) { int error = 0, in, family, need_free = 0, interr, i; - int interr_tbl[3] = { 152, 156, 153}; enum { OP_ADD, /* add rule */ OP_REM, /* remove rule */ OP_ZERO /* zero statistics and counters */ }