On Thu, Jun 24, 2021 at 11:49 AM Paolo Abeni [off-list ref] wrote:
On Wed, 2021-06-23 at 12:43 -0700, Eric Dumazet wrote:
quoted
From: Eric Dumazet <edumazet@google.com>
First problem is that optlen is fetched without checking
there is more than one byte to parse.
Fix this by taking care of IPV6_TLV_PAD1 before
fetching optlen (under appropriate sanity checks against len)
Second problem is that IPV6_TLV_PADN checks of zero
padding are performed before the check of remaining length.
Fixes: c1412fce7ecc ("net/ipv6/exthdrs.c: Strict PadN option checking")
Perhaps even:
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
for the first issue?
+ if (nh[off] == IPV6_TLV_PAD1) {quoted
optlen = 1;
It looks like the above assignment is not needed anymore.
Other than that LGTM,
Thanks for the review, I am sending the v2.