Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion expr/ct.go
Original file line number Diff line number Diff line change
Expand Up @@ -414,10 +414,10 @@ func (c *CtTimeout) unmarshal(fam byte, data []byte) error {
c.L4Proto = ad.Uint8()
case NFTA_CT_TIMEOUT_DATA:
decoder, err := netlink.NewAttributeDecoder(ad.Bytes())
decoder.ByteOrder = binary.BigEndian
if err != nil {
return err
}
decoder.ByteOrder = binary.BigEndian
for decoder.Next() {
switch c.L4Proto {
case unix.IPPROTO_UDP:
Expand Down
28 changes: 28 additions & 0 deletions expr/ct_timeout_malformed_test.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
package expr

import (
"testing"

"github.com/mdlayher/netlink"
)

// TestCtTimeoutUnmarshalMalformedNestedAttr verifies that a truncated nested
// NFTA_CT_TIMEOUT_DATA attribute returns an error instead of panicking.
// Regression for https://github.com/google/nftables/issues/367
func TestCtTimeoutUnmarshalMalformedNestedAttr(t *testing.T) {
t.Parallel()

data, err := netlink.MarshalAttributes([]netlink.Attribute{
// One-byte payload is shorter than an NLA header, so
// NewAttributeDecoder returns (nil, err).
{Type: NFTA_CT_TIMEOUT_DATA, Data: []byte{0xff}},
})
if err != nil {
t.Fatal(err)
}

ct := &CtTimeout{}
if err := ct.unmarshal(0, data); err == nil {
t.Fatal("expected error unmarshaling malformed nested attribute, got nil")
}
}
Loading