Commit 9ccff83b authored by Xin Long's avatar Xin Long Committed by Florian Westphal
Browse files

netfilter: bridge: call pskb_may_pull in br_nf_check_hbh_len



When checking Hop-by-hop option header, if the option data is in
nonlinear area, it should do pskb_may_pull instead of discarding
the skb as a bad IPv6 packet.

Signed-off-by: default avatarXin Long <lucien.xin@gmail.com>
Reviewed-by: default avatarSimon Horman <simon.horman@corigine.com>
Acked-by: default avatarNikolay Aleksandrov <razor@blackwall.org>
Reviewed-by: default avatarAaron Conole <aconole@redhat.com>
Signed-off-by: default avatarFlorian Westphal <fw@strlen.de>
parent 4386b921
Loading
Loading
Loading
Loading
+9 −5
Original line number Diff line number Diff line
@@ -45,14 +45,18 @@
 */
static int br_nf_check_hbh_len(struct sk_buff *skb)
{
	unsigned char *raw = (u8 *)(ipv6_hdr(skb) + 1);
	int len, off = sizeof(struct ipv6hdr);
	unsigned char *nh;
	u32 pkt_len;
	const unsigned char *nh = skb_network_header(skb);
	int off = raw - nh;
	int len = (raw[1] + 1) << 3;

	if ((raw + len) - skb->data > skb_headlen(skb))
	if (!pskb_may_pull(skb, off + 8))
		goto bad;
	nh = (unsigned char *)(ipv6_hdr(skb) + 1);
	len = (nh[1] + 1) << 3;

	if (!pskb_may_pull(skb, off + len))
		goto bad;
	nh = skb_network_header(skb);

	off += 2;
	len -= 2;