mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 09:36:22 +02:00
netfilter: nf_reject: skip iphdr options when looking for icmp header
Not a big deal but this hould have used the real ip header length and not the
base header size. As-is, if there are options then
nf_skb_is_icmp_unreach() result will be random.
Fixes: db99b2f2b3 ("netfilter: nf_reject: don't reply to icmp error messages")
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
This commit is contained in:
parent
e409c23c2d
commit
af8d6ae09c
|
|
@ -89,7 +89,7 @@ static bool nf_skb_is_icmp_unreach(const struct sk_buff *skb)
|
|||
if (iph->protocol != IPPROTO_ICMP)
|
||||
return false;
|
||||
|
||||
thoff = skb_network_offset(skb) + sizeof(*iph);
|
||||
thoff = skb_network_offset(skb) + ip_hdrlen(skb);
|
||||
|
||||
tp = skb_header_pointer(skb,
|
||||
thoff + offsetof(struct icmphdr, type),
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user