Commit fd62e09b authored by David S. Miller's avatar David S. Miller

tcp: Validate route interface in early demux.

Otherwise we might violate reverse path filtering.
Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
parent 3e428fe0
...@@ -1676,6 +1676,7 @@ int tcp_v4_early_demux(struct sk_buff *skb) ...@@ -1676,6 +1676,7 @@ int tcp_v4_early_demux(struct sk_buff *skb)
struct net *net = dev_net(skb->dev); struct net *net = dev_net(skb->dev);
const struct iphdr *iph; const struct iphdr *iph;
const struct tcphdr *th; const struct tcphdr *th;
struct net_device *dev;
struct sock *sk; struct sock *sk;
int err; int err;
...@@ -1695,10 +1696,11 @@ int tcp_v4_early_demux(struct sk_buff *skb) ...@@ -1695,10 +1696,11 @@ int tcp_v4_early_demux(struct sk_buff *skb)
if (!pskb_may_pull(skb, ip_hdrlen(skb) + th->doff * 4)) if (!pskb_may_pull(skb, ip_hdrlen(skb) + th->doff * 4))
goto out_err; goto out_err;
dev = skb->dev;
sk = __inet_lookup_established(net, &tcp_hashinfo, sk = __inet_lookup_established(net, &tcp_hashinfo,
iph->saddr, th->source, iph->saddr, th->source,
iph->daddr, th->dest, iph->daddr, th->dest,
skb->dev->ifindex); dev->ifindex);
if (sk) { if (sk) {
skb->sk = sk; skb->sk = sk;
skb->destructor = sock_edemux; skb->destructor = sock_edemux;
...@@ -1707,11 +1709,15 @@ int tcp_v4_early_demux(struct sk_buff *skb) ...@@ -1707,11 +1709,15 @@ int tcp_v4_early_demux(struct sk_buff *skb)
if (dst) if (dst)
dst = dst_check(dst, 0); dst = dst_check(dst, 0);
if (dst) { if (dst) {
struct rtable *rt = (struct rtable *) dst;
if (rt->rt_iif == dev->ifindex) {
skb_dst_set_noref(skb, dst); skb_dst_set_noref(skb, dst);
err = 0; err = 0;
} }
} }
} }
}
out_err: out_err:
return err; return err;
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment