summaryrefslogtreecommitdiffstats
path: root/net/ipv6/netfilter/ip6t_REJECT.c
diff options
context:
space:
mode:
authorPablo Neira Ayuso2015-03-21 20:20:23 +0100
committerPablo Neira Ayuso2015-03-22 20:02:46 +0100
commite35158e40110270600698f19bda5e21d8ce709d7 (patch)
treef647926624f1a12465f1da8fff55689032a62a35 /net/ipv6/netfilter/ip6t_REJECT.c
parentnetfilter: nf_tables: reject NFT_SET_ELEM_INTERVAL_END flag for non-interval ... (diff)
downloadkernel-qcow2-linux-e35158e40110270600698f19bda5e21d8ce709d7.tar.gz
kernel-qcow2-linux-e35158e40110270600698f19bda5e21d8ce709d7.tar.xz
kernel-qcow2-linux-e35158e40110270600698f19bda5e21d8ce709d7.zip
netfilter: ip6t_REJECT: check for IP6T_F_PROTO
Make sure IP6T_F_PROTO is set to enforce layer 4 protocol matching from the ip6_tables core. Suggested-by: Patrick McHardy <kaber@trash.net> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Diffstat (limited to 'net/ipv6/netfilter/ip6t_REJECT.c')
-rw-r--r--net/ipv6/netfilter/ip6t_REJECT.c3
1 files changed, 2 insertions, 1 deletions
diff --git a/net/ipv6/netfilter/ip6t_REJECT.c b/net/ipv6/netfilter/ip6t_REJECT.c
index 544b0a9da1b5..12331efd49cf 100644
--- a/net/ipv6/netfilter/ip6t_REJECT.c
+++ b/net/ipv6/netfilter/ip6t_REJECT.c
@@ -83,7 +83,8 @@ static int reject_tg6_check(const struct xt_tgchk_param *par)
return -EINVAL;
} else if (rejinfo->with == IP6T_TCP_RESET) {
/* Must specify that it's a TCP packet */
- if (e->ipv6.proto != IPPROTO_TCP ||
+ if (!(e->ipv6.flags & IP6T_F_PROTO) ||
+ e->ipv6.proto != IPPROTO_TCP ||
(e->ipv6.invflags & XT_INV_PROTO)) {
pr_info("TCP_RESET illegal for non-tcp\n");
return -EINVAL;