[PATCH] IPV6: Ensure to have hop-by-hop options in our header of &sk_buff.
[IPV6]: Ensure to have hop-by-hop options in our header of &sk_buff. Signed-off-by: YOSHIFUJI Hideaki <yoshfuji@linux-ipv6.org> Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
This commit is contained in:
committed by
Greg Kroah-Hartman
parent
00905d5430
commit
9c974666ab
@@ -489,6 +489,18 @@ int ipv6_parse_hopopts(struct sk_buff *skb, int nhoff)
|
||||
{
|
||||
struct inet6_skb_parm *opt = IP6CB(skb);
|
||||
|
||||
/*
|
||||
* skb->nh.raw is equal to skb->data, and
|
||||
* skb->h.raw - skb->nh.raw is always equal to
|
||||
* sizeof(struct ipv6hdr) by definition of
|
||||
* hop-by-hop options.
|
||||
*/
|
||||
if (!pskb_may_pull(skb, sizeof(struct ipv6hdr) + 8) ||
|
||||
!pskb_may_pull(skb, sizeof(struct ipv6hdr) + ((skb->h.raw[1] + 1) << 3))) {
|
||||
kfree_skb(skb);
|
||||
return -1;
|
||||
}
|
||||
|
||||
opt->hop = sizeof(struct ipv6hdr);
|
||||
if (ip6_parse_tlv(tlvprochopopt_lst, skb)) {
|
||||
skb->h.raw += (skb->h.raw[1]+1)<<3;
|
||||
|
||||
Reference in New Issue
Block a user