[PATCH] netfilter: nf_conntrack_h323: fix NULL pointer deref in decode_seqof()
From: Henry Martin
Date: Fri Oct 09 2026 - 08:57:49 EST
The eight supportedPrefixes table entries (_H310Caps, _H320Caps,
_H321Caps, _H322Caps, _H323Caps, _H324Caps, _VoiceCaps and
_T120OnlyCaps, all reached through the _SupportedProtocols CHOICE)
are declared SEQOF,SEMI with fields=NULL. decode_seqof()
dereferences f->fields on the first loop iteration whenever the
attacker-controlled SEMI count is non-zero, causing a NULL pointer
dereference.
Return H323_ERROR_BOUND when the nested field pointer is NULL.
This issue was discovered by Tencent CodeBuddy Security.
Cc: stable@xxxxxxxxxxxxxxx
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Henry Martin <bsdhenrymartin@xxxxxxxxx>
---
net/netfilter/nf_conntrack_h323_asn1.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/net/netfilter/nf_conntrack_h323_asn1.c b/net/netfilter/nf_conntrack_h323_asn1.c
index 6830c9da3507..4d66db5bf5f7 100644
--- a/net/netfilter/nf_conntrack_h323_asn1.c
+++ b/net/netfilter/nf_conntrack_h323_asn1.c
@@ -692,6 +692,13 @@ static int decode_seqof(struct bitstr *bs, const struct field_t *f,
/* Decode nested field */
son = f->fields;
+ /*
+ * Malformed table entries may carry a NULL fields pointer (e.g.
+ * the *_Caps.supportedPrefixes SEQOF,SEMI rows); treat them as
+ * undecodable instead of dereferencing NULL when count > 0.
+ */
+ if (!son)
+ return H323_ERROR_BOUND;
if (base)
base -= son->offset;
for (i = 0; i < count; i++) {
--
2.43.7