From 4870530f13e1b3c3c14ce09bde5bc55ee3814595 Mon Sep 17 00:00:00 2001 From: Paras Singh Jain Date: Mon, 15 Jan 2018 16:53:18 +0530 Subject: [PATCH] netfilter: contrack: Adding check for SIP/2.0 Packets arriving at SIP port will now be checked for SIP/2.0 before getting tagged as SIP packet. Added helper functions strnstr and strnstrn for checking substring in a string in case of non null termination. Change-Id: Ia7d6a3ac5dd1e5f0ce97ee9f6d0c13f16d9dd7f2 Acked-by: Vinisha Varre Signed-off-by: Paras Singh Jain --- net/netfilter/nf_conntrack_sip.c | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/net/netfilter/nf_conntrack_sip.c b/net/netfilter/nf_conntrack_sip.c index 21fa55704902..66242828b6c8 100644 --- a/net/netfilter/nf_conntrack_sip.c +++ b/net/netfilter/nf_conntrack_sip.c @@ -1989,6 +1989,11 @@ static int sip_help_tcp(struct sk_buff *skb, unsigned int protoff, datalen = skb->len - dataoff; if (datalen < strlen("SIP/2.0 200")) return NF_ACCEPT; + + /* Check if the header contains SIP version */ + if (!strnstr(dptr, "SIP/2.0", datalen)) + return NF_ACCEPT; + #ifdef CONFIG_NF_CONNTRACK_SIP_SEGMENTATION /* here we save the original datalength and data offset of the skb, this * is needed later to split combined skbs @@ -2125,6 +2130,10 @@ static int sip_help_udp(struct sk_buff *skb, unsigned int protoff, if (datalen < strlen("SIP/2.0 200")) return NF_ACCEPT; + /* Check if the header contains SIP version */ + if (!strnstr(dptr, "SIP/2.0", datalen)) + return NF_ACCEPT; + return process_sip_msg(skb, ct, protoff, dataoff, &dptr, &datalen); }