commit | ec3d837aac5dca7cb8a69c9f101690c182da79c4 | [log] [tgz] |
---|---|---|
author | Stanislav Fomichev <sdf@google.com> | Wed Dec 05 20:40:48 2018 -0800 |
committer | Alexei Starovoitov <ast@kernel.org> | Fri Dec 07 13:38:29 2018 -0800 |
tree | b4943b459ce0aa731a75f27543b536fc8ba070bd | |
parent | 13e56ec2cc9860aa22e01ffc7a3160f35a96b728 [diff] |
net/flow_dissector: correctly cap nhoff and thoff in case of BPF We want to make sure that the following condition holds: 0 <= nhoff <= thoff <= skb->len BPF program can set out-of-bounds nhoff and thoff, which is dangerous, see recent commit d0c081b49137 ("flow_dissector: properly cap thoff field")'. Signed-off-by: Stanislav Fomichev <sdf@google.com> Acked-by: Song Liu <songliubraving@fb.com> Signed-off-by: Alexei Starovoitov <ast@kernel.org>