ip: ip_options_compile() resilient to NULL skb route
Scot Doyle demonstrated ip_options_compile() could be called with an skb without an attached route, using a setup involving a bridge, netfilter, and forged IP packets. Let's make ip_options_compile() and ip_options_rcv_srr() a bit more robust, instead of changing bridge/netfilter code. With help from Hiroaki SHIMODA. Reported-by: Scot Doyle <lkml@scotdoyle.com> Tested-by: Scot Doyle <lkml@scotdoyle.com> Signed-off-by: Eric Dumazet <eric.dumazet@gmail.com> Cc: Stephen Hemminger <shemminger@vyatta.com> Acked-by: Hiroaki SHIMODA <shimoda.hiroaki@gmail.com> Signed-off-by: David S. Miller <davem@davemloft.net>
This commit is contained in:
parent
49b4947aae
commit
c65353daf1
|
@ -329,7 +329,7 @@ int ip_options_compile(struct net *net,
|
||||||
pp_ptr = optptr + 2;
|
pp_ptr = optptr + 2;
|
||||||
goto error;
|
goto error;
|
||||||
}
|
}
|
||||||
if (skb) {
|
if (rt) {
|
||||||
memcpy(&optptr[optptr[2]-1], &rt->rt_spec_dst, 4);
|
memcpy(&optptr[optptr[2]-1], &rt->rt_spec_dst, 4);
|
||||||
opt->is_changed = 1;
|
opt->is_changed = 1;
|
||||||
}
|
}
|
||||||
|
@ -371,7 +371,7 @@ int ip_options_compile(struct net *net,
|
||||||
goto error;
|
goto error;
|
||||||
}
|
}
|
||||||
opt->ts = optptr - iph;
|
opt->ts = optptr - iph;
|
||||||
if (skb) {
|
if (rt) {
|
||||||
memcpy(&optptr[optptr[2]-1], &rt->rt_spec_dst, 4);
|
memcpy(&optptr[optptr[2]-1], &rt->rt_spec_dst, 4);
|
||||||
timeptr = (__be32*)&optptr[optptr[2]+3];
|
timeptr = (__be32*)&optptr[optptr[2]+3];
|
||||||
}
|
}
|
||||||
|
@ -603,7 +603,7 @@ int ip_options_rcv_srr(struct sk_buff *skb)
|
||||||
unsigned long orefdst;
|
unsigned long orefdst;
|
||||||
int err;
|
int err;
|
||||||
|
|
||||||
if (!opt->srr)
|
if (!opt->srr || !rt)
|
||||||
return 0;
|
return 0;
|
||||||
|
|
||||||
if (skb->pkt_type != PACKET_HOST)
|
if (skb->pkt_type != PACKET_HOST)
|
||||||
|
|
Loading…
Reference in New Issue