mirror of
https://github.com/torvalds/linux.git
synced 2026-07-28 01:55:51 +02:00
xfrm: check family before comparing addresses in migrate
When migrating between different address families, xfrm_addr_equal()
cannot meaningfully compare addresses, different lengths.
Only call xfrm_addr_equal() when families match, and take
the xfrm_state_insert() path when addresses are equal.
Fixes: 80c9abaabf ("[XFRM]: Extension for dynamic update of endpoint address(es)")
Signed-off-by: Antony Antony <antony.antony@secunet.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
This commit is contained in:
parent
8de53883a4
commit
b2cb192b95
|
|
@ -2159,10 +2159,11 @@ int xfrm_state_migrate_install(const struct xfrm_state *x,
|
|||
struct xfrm_user_offload *xuo,
|
||||
struct netlink_ext_ack *extack)
|
||||
{
|
||||
if (xfrm_addr_equal(&x->id.daddr, &m->new_daddr, m->new_family)) {
|
||||
if (m->new_family == m->old_family &&
|
||||
xfrm_addr_equal(&x->id.daddr, &m->new_daddr, m->new_family)) {
|
||||
/*
|
||||
* Care is needed when the destination address
|
||||
* of the state is to be updated as it is a part of triplet.
|
||||
* Care is needed when the destination address of the state is
|
||||
* to be updated as it is a part of triplet.
|
||||
*/
|
||||
xfrm_state_insert(xc);
|
||||
} else {
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user