Browse Source

fix INIT bounds checks and eim_nat port uint16_t wrap

congestion
Evgeny 5 months ago
parent
commit
6c2aeb69a1
  1. 4
      src/eim_nat.c
  2. 4
      src/etcp_connections.c

4
src/eim_nat.c

@ -83,11 +83,11 @@ static uint16_t eim_nat_alloc_port(struct eim_nat_ctx* ctx) {
if (ctx->table[ctx->next_port].state == EIM_NAT_ENTRY_FREE) {
uint16_t port = ctx->next_port;
ctx->next_port++;
if (ctx->next_port > ctx->port_end) ctx->next_port = ctx->port_start;
if (ctx->next_port > ctx->port_end || ctx->next_port < ctx->port_start) ctx->next_port = ctx->port_start;
return port;
}
ctx->next_port++;
if (ctx->next_port > ctx->port_end) ctx->next_port = ctx->port_start;
if (ctx->next_port > ctx->port_end || ctx->next_port < ctx->port_start) ctx->next_port = ctx->port_start;
} while (ctx->next_port != start);
return 0;
}

4
src/etcp_connections.c

@ -1393,7 +1393,7 @@ void etcp_connections_read_callback_socket(socket_t sock, void* arg) {
errorcode=7;
goto ec_fr;
}
if (pkt_len<12) {
if (pkt_len<15) {
DEBUG_ERROR(DEBUG_CATEGORY_CONNECTION, "decrypted packet too short for INIT header, pkt_len=%zu from %s", pkt_len, sockaddr_storage_to_str(&addr).str);
errorcode=7;
goto ec_fr;
@ -1769,7 +1769,7 @@ process_decrypted:
uint8_t code = pkt->data[offset++];
if (code == ETCP_INIT_RESPONSE || code == ETCP_INIT_RESPONSE_NOINIT) {
// Parse response
if (pkt_len < 22) { errorcode = 46; DEBUG_ERROR(DEBUG_CATEGORY_ETCP, "INIT_RESPONSE too short: pkt_len=%zu", pkt_len); goto ec_fr; }
// ETCP_INIT_RESPONSE (0x03) - reset entire ETCP_CONN
// ETCP_INIT_RESPONSE_NOINIT (0x05) - no reset
uint64_t server_node_id = 0;

Loading…
Cancel
Save