mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-07-22 02:17:36 -04:00
netfilter: nf_reject: skip iphdr options when looking for icmp header
Not a big deal but this hould have used the real ip header length and not the
base header size. As-is, if there are options then
nf_skb_is_icmp_unreach() result will be random.
Fixes: db99b2f2b3 ("netfilter: nf_reject: don't reply to icmp error messages")
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
This commit is contained in:
committed by
Pablo Neira Ayuso
parent
e409c23c2d
commit
af8d6ae09c
@@ -89,7 +89,7 @@ static bool nf_skb_is_icmp_unreach(const struct sk_buff *skb)
|
||||
if (iph->protocol != IPPROTO_ICMP)
|
||||
return false;
|
||||
|
||||
thoff = skb_network_offset(skb) + sizeof(*iph);
|
||||
thoff = skb_network_offset(skb) + ip_hdrlen(skb);
|
||||
|
||||
tp = skb_header_pointer(skb,
|
||||
thoff + offsetof(struct icmphdr, type),
|
||||
|
||||
Reference in New Issue
Block a user