mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 17:47:41 +02:00
netfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto()
Add sanity check for iph->ihl field in nf_flow_ip4_tunnel_proto() before
using it to compute the header size, avoiding out-of-bounds access with
malformed IP headers.
While at it, use iph->protocol instead of the hardcoded IPPROTO_IPIP
constant when setting ctx->tun.proto and reference ctx->tun.hdr_size
when updating ctx->offset.
Fixes: ab427db178 ("netfilter: flowtable: Add IPIP rx sw acceleration")
Signed-off-by: Lorenzo Bianconi <lorenzo@kernel.org>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
This commit is contained in:
parent
c8b6f36f76
commit
84460b6443
|
|
@ -326,8 +326,10 @@ static bool nf_flow_ip4_tunnel_proto(struct nf_flowtable_ctx *ctx,
|
|||
return false;
|
||||
|
||||
iph = (struct iphdr *)(skb_network_header(skb) + ctx->offset);
|
||||
size = iph->ihl << 2;
|
||||
if (iph->ihl < 5)
|
||||
return false;
|
||||
|
||||
size = iph->ihl << 2;
|
||||
if (ip_is_fragment(iph) || unlikely(ip_has_options(size)))
|
||||
return false;
|
||||
|
||||
|
|
@ -335,9 +337,9 @@ static bool nf_flow_ip4_tunnel_proto(struct nf_flowtable_ctx *ctx,
|
|||
return false;
|
||||
|
||||
if (iph->protocol == IPPROTO_IPIP) {
|
||||
ctx->tun.proto = IPPROTO_IPIP;
|
||||
ctx->tun.proto = iph->protocol;
|
||||
ctx->tun.hdr_size = size;
|
||||
ctx->offset += size;
|
||||
ctx->offset += ctx->tun.hdr_size;
|
||||
}
|
||||
|
||||
return true;
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user