Project

General

Profile

Actions

Bug #5309

closed

CIDR prefix calculation fails on big endian archs

Added by Sascha Steinbiss 5 months ago. Updated 3 months ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

While trying to build 6.0.5 on Debian's s390x port, we noticed that tests segfault in the new version (see https://ci.debian.net/data/autopkgtest/testing/s390x/s/suricata/21160408/log.gz). Tracking this down, it seems that CIDRFromMask() returns -1 when trying to determine a network prefix length for a given netmask (e.g. 24 for 255.255.255.0). This causes DetectAddressParseSingle() to return NULL and hence the test to try and dereference a null pointer, causing the segfault.

I compared values passed into CIDRFromMask() via gdb on amd64 and s390x and found that they are different:

amd64


...
Test AddressTestCutIPv401                                         : 
Breakpoint 1, CIDRFromMask (netmask=16777215) at util-cidr.c:34
...

s390x


...
Test AddressTestCutIPv401                                         : 
Breakpoint 1, CIDRFromMask (netmask=4294967040) at util-cidr.c:34
...

My patch at https://gist.github.com/satta/7406fe735d8b449a4c9af73822d2bc9a fixes the code for both architectures.


Subtasks 2 (0 open2 closed)

Bug #5344: CIDR prefix calculation fails on big endian archs (6.0.x backport)ClosedJeff LucovskyActions
Bug #5345: CIDR prefix calculation fails on big endian archs (5.0.x backport)ClosedJeff LucovskyActions
Actions #1

Updated by Victor Julien 5 months ago

  • Status changed from New to In Review
  • Assignee changed from OISF Dev to Sascha Steinbiss
  • Target version changed from TBD to 7.0rc1

https://github.com/OISF/suricata/pull/7332

Possibly needs backport to 5.0 as well.

Actions #2

Updated by Jeff Lucovsky 5 months ago

  • Label Needs backport to 5.0 added
  • Label deleted (Needs backport)
Actions #3

Updated by Jeff Lucovsky 5 months ago

  • Copied to Bug #5344: CIDR prefix calculation fails on big endian archs (6.0.x backport) added
Actions #4

Updated by Jeff Lucovsky 5 months ago

  • Copied to Bug #5345: CIDR prefix calculation fails on big endian archs (5.0.x backport) added
Actions #5

Updated by Jeff Lucovsky 4 months ago

  • Status changed from In Review to Resolved
Actions #6

Updated by Victor Julien 3 months ago

  • Status changed from Resolved to Closed
Actions #7

Updated by Victor Julien 3 months ago

  • Label deleted (Needs backport to 5.0, Needs backport to 6.0)
Actions

Also available in: Atom PDF