Project

General

Profile

Actions

Bug #9122

open
VJ VJ

firewall: file.data auto-prior-accept bypass

Bug #9122: firewall: file.data auto-prior-accept bypass

Added by Victor Julien 5 days ago. Updated 3 days ago.

Status:
In Review
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

The filedata inspect engine (file_data keyword) returned NO_MATCH for every non-matching file, also when the transaction had already moved past the engine's progress — when no further file can arrive for that direction.

In firewall mode an LTE rule (accept:tx at some progress) becomes definitive only when the engine returns a definitive result. Because NO_MATCH never becomes definitive, the rule stays pending indefinitely, and the fail-closed default app policy for the hook is not applied. Traffic no rule accepts is not dropped.

The observable case is the streaming registration: the http2 request body. For an LTE rule allowing only request bodies matching %PDF: a request uploads a non-matching body and is closed (END_STREAM) while the response is still in progress — the stream tx is still open. The engine's eof condition (tx progress moved past request_data) holds, but the engine kept returning NO_MATCH. The rule never became definitive, so the fail-closed default (drop:flow) was not applied when the request became final; it applied only late (at tx/capture end) and without the default policy alert.

file_data is registered for the http1 request body, the http2 request stream body and the smtp request data. In http1 and smtp the engine eof coincides with the tx end state, so the tx-end path made the rule definitive pre-fix, masking the issue; the http2 request body is the observable case.

Fix: return CANT_MATCH_FILES once the tx progress moved beyond the engine's progress (no file, or all files scanned), making the rule definitive at request eof. The existing per-file state reset keeps the rule matchable if the tx grows another file.


Subtasks 1 (1 open — 0 closed)

Bug #9127: firewall: file.data auto-prior-accept bypass (8.0.x backport)AssignedVictor JulienActions

Related issues 1 (1 open — 0 closed)

Related to Suricata - Bug #8944: firewall: auto-accept-prior-states not honored when a same-hook drop rule leads the candidate listIn ProgressVictor JulienActions

VJ Updated by Victor Julien 5 days ago Actions #1

  • Related to Bug #8944: firewall: auto-accept-prior-states not honored when a same-hook drop rule leads the candidate list added

VJ Updated by Victor Julien 4 days ago Actions #2

  • Status changed from In Progress to In Review
  • Label Needs backport to 8.0 added

OT Updated by OISF Ticketbot 4 days ago Actions #3

  • Subtask #9127 added

OT Updated by OISF Ticketbot 4 days ago Actions #4

  • Label deleted (Needs backport to 8.0)

VJ Updated by Victor Julien 3 days ago Actions #5

  • Status changed from In Review to Resolved

JI Updated by Jason Ish 3 days ago Actions #6

  • Status changed from Resolved to In Review
Actions

Also available in: PDF Atom