netfilter: nf_flow_table: check ttl value in flow offload data path
authorTaehee Yoo <ap420073@gmail.com>
Mon, 29 Apr 2019 16:55:54 +0000 (01:55 +0900)
committerPablo Neira Ayuso <pablo@netfilter.org>
Tue, 30 Apr 2019 11:56:19 +0000 (13:56 +0200)
commit33cc3c0cfa64c86b6c4bbee86997aea638534931
tree8bfaf82f1fc93007863fb85b1ae2146600357497
parent26a302afbe328ecb7507cae2035d938e6635131b
netfilter: nf_flow_table: check ttl value in flow offload data path

nf_flow_offload_ip_hook() and nf_flow_offload_ipv6_hook() do not check
ttl value. So, ttl value overflow may occur.

Fixes: 97add9f0d66d ("netfilter: flow table support for IPv4")
Fixes: 0995210753a2 ("netfilter: flow table support for IPv6")
Signed-off-by: Taehee Yoo <ap420073@gmail.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
net/netfilter/nf_flow_table_ip.c