]> git.ipfire.org Git - thirdparty/linux.git/commit
netfilter: conntrack_irc: fix possible out-of-bounds read
authorFlorian Westphal <fw@strlen.de>
Wed, 27 May 2026 10:20:19 +0000 (12:20 +0200)
committerPablo Neira Ayuso <pablo@netfilter.org>
Mon, 1 Jun 2026 11:43:53 +0000 (13:43 +0200)
commit66eba0ffce3b7e11449946b4cbbef8ea36112f56
tree1dad47a5ac397e541d19b299b1ae693af8fff0a9
parent2fcba19caaeb2a33017459d3430f057967bb91b6
netfilter: conntrack_irc: fix possible out-of-bounds read

When parsing fails after we've matched the command string we
should bail out instead of trying to match a different command.

This helper should be deprecated, given prevalence of TLS I doubt it has
any relevance in 2026.

Fixes: 869f37d8e48f ("[NETFILTER]: nf_conntrack/nf_nat: add IRC helper port")
Closes: https://sashiko.dev/#/patchset/20260525182924.28456-1-fw%40strlen.de
Signed-off-by: Florian Westphal <fw@strlen.de>
Reviewed-by: Fernando Fernandez Mancera <fmancera@suse.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
net/netfilter/nf_conntrack_irc.c