| From 1dc5873e024f47162d8853b2dba592022680b94f Mon Sep 17 00:00:00 2001 |
| From: Haishuang Yan <yanhaishuang@cmss.chinamobile.com> |
| Date: Tue, 17 Mar 2020 10:02:53 +0800 |
| Subject: [PATCH] netfilter: flowtable: reload ip{v6}h in nf_flow_tuple_ip{v6} |
| |
| commit 41e9ec5a54f95eee1a57c8d26ab70e0492548c1b upstream. |
| |
| Since pskb_may_pull may change skb->data, so we need to reload ip{v6}h at |
| the right place. |
| |
| Fixes: a908fdec3dda ("netfilter: nf_flow_table: move ipv6 offload hook code to nf_flow_table") |
| Fixes: 7d2086871762 ("netfilter: nf_flow_table: move ipv4 offload hook code to nf_flow_table") |
| Signed-off-by: Haishuang Yan <yanhaishuang@cmss.chinamobile.com> |
| Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org> |
| Signed-off-by: Paul Gortmaker <paul.gortmaker@windriver.com> |
| |
| diff --git a/net/netfilter/nf_flow_table_ip.c b/net/netfilter/nf_flow_table_ip.c |
| index b9e7dd6e60ce..e92aa6b7eb80 100644 |
| --- a/net/netfilter/nf_flow_table_ip.c |
| +++ b/net/netfilter/nf_flow_table_ip.c |
| @@ -189,6 +189,7 @@ static int nf_flow_tuple_ip(struct sk_buff *skb, const struct net_device *dev, |
| if (!pskb_may_pull(skb, thoff + sizeof(*ports))) |
| return -1; |
| |
| + iph = ip_hdr(skb); |
| ports = (struct flow_ports *)(skb_network_header(skb) + thoff); |
| |
| tuple->src_v4.s_addr = iph->saddr; |
| @@ -449,6 +450,7 @@ static int nf_flow_tuple_ipv6(struct sk_buff *skb, const struct net_device *dev, |
| if (!pskb_may_pull(skb, thoff + sizeof(*ports))) |
| return -1; |
| |
| + ip6h = ipv6_hdr(skb); |
| ports = (struct flow_ports *)(skb_network_header(skb) + thoff); |
| |
| tuple->src_v6 = ip6h->saddr; |
| -- |
| 2.7.4 |
| |