On Mon, Dec 3, 2012 at 6:04 AM, Pablo Neira Ayuso [off-list ref] wrote:
On Thu, Nov 29, 2012 at 10:35:45AM -0800, Jesse Gross wrote:
quoted
@@ -159,9 +162,10 @@ int ipv6_find_hdr(const struct sk_buff *skb, unsigned int *offset,
}
len = skb->len - start;
- while (nexthdr != target) {
If the offset is set as parameter via ipv6_find_hdr, we now are always
entering the loop even if we found the target header we're looking
for, before that didn't happen.
Something seems wrong here to me.
If the target header is a routing header then you might still need to
continue searching because the first one that you see could be empty.