commit | 2638fd0f92d4397884fd991d8f4925cb3f081901 | [log] [tgz] |
---|---|---|
author | Eric Dumazet <edumazet@google.com> | Mon Apr 03 10:55:11 2017 -0700 |
committer | Pablo Neira Ayuso <pablo@netfilter.org> | Sat Apr 08 22:24:19 2017 +0200 |
tree | f7c6cce4be9a84861a75ee58a2106a23cd79b91a | |
parent | 0b9aefea860063bb39e36bd7fe6c7087fed0ba87 [diff] |
netfilter: xt_TCPMSS: add more sanity tests on tcph->doff Denys provided an awesome KASAN report pointing to an use after free in xt_TCPMSS I have provided three patches to fix this issue, either in xt_TCPMSS or in xt_tcpudp.c. It seems xt_TCPMSS patch has the smallest possible impact. Signed-off-by: Eric Dumazet <edumazet@google.com> Reported-by: Denys Fedoryshchenko <nuclearcat@nuclearcat.com> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>