提交 c65353da 编写于 作者: E Eric Dumazet 提交者: David S. Miller

ip: ip_options_compile() resilient to NULL skb route

Scot Doyle demonstrated ip_options_compile() could be called with an skb
without an attached route, using a setup involving a bridge, netfilter,
and forged IP packets.

Let's make ip_options_compile() and ip_options_rcv_srr() a bit more
robust, instead of changing bridge/netfilter code.

With help from Hiroaki SHIMODA.
Reported-by: NScot Doyle <lkml@scotdoyle.com>
Tested-by: NScot Doyle <lkml@scotdoyle.com>
Signed-off-by: NEric Dumazet <eric.dumazet@gmail.com>
Cc: Stephen Hemminger <shemminger@vyatta.com>
Acked-by: NHiroaki SHIMODA <shimoda.hiroaki@gmail.com>
Signed-off-by: NDavid S. Miller <davem@davemloft.net>
上级 49b4947a
...@@ -329,7 +329,7 @@ int ip_options_compile(struct net *net, ...@@ -329,7 +329,7 @@ int ip_options_compile(struct net *net,
pp_ptr = optptr + 2; pp_ptr = optptr + 2;
goto error; goto error;
} }
if (skb) { if (rt) {
memcpy(&optptr[optptr[2]-1], &rt->rt_spec_dst, 4); memcpy(&optptr[optptr[2]-1], &rt->rt_spec_dst, 4);
opt->is_changed = 1; opt->is_changed = 1;
} }
...@@ -371,7 +371,7 @@ int ip_options_compile(struct net *net, ...@@ -371,7 +371,7 @@ int ip_options_compile(struct net *net,
goto error; goto error;
} }
opt->ts = optptr - iph; opt->ts = optptr - iph;
if (skb) { if (rt) {
memcpy(&optptr[optptr[2]-1], &rt->rt_spec_dst, 4); memcpy(&optptr[optptr[2]-1], &rt->rt_spec_dst, 4);
timeptr = (__be32*)&optptr[optptr[2]+3]; timeptr = (__be32*)&optptr[optptr[2]+3];
} }
...@@ -603,7 +603,7 @@ int ip_options_rcv_srr(struct sk_buff *skb) ...@@ -603,7 +603,7 @@ int ip_options_rcv_srr(struct sk_buff *skb)
unsigned long orefdst; unsigned long orefdst;
int err; int err;
if (!opt->srr) if (!opt->srr || !rt)
return 0; return 0;
if (skb->pkt_type != PACKET_HOST) if (skb->pkt_type != PACKET_HOST)
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册