| From ea9b61cc020359b7b81d80504f3d6959090cb3d8 Mon Sep 17 00:00:00 2001 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Tue, 22 Jun 2021 12:24:50 +0800 |
| Subject: net/ipv4: swap flow ports when validating source |
| |
| From: Miao Wang <shankerwangmiao@gmail.com> |
| |
| [ Upstream commit c69f114d09891adfa3e301a35d9e872b8b7b5a50 ] |
| |
| When doing source address validation, the flowi4 struct used for |
| fib_lookup should be in the reverse direction to the given skb. |
| fl4_dport and fl4_sport returned by fib4_rules_early_flow_dissect |
| should thus be swapped. |
| |
| Fixes: 5a847a6e1477 ("net/ipv4: Initialize proto and ports in flow struct") |
| Signed-off-by: Miao Wang <shankerwangmiao@gmail.com> |
| Reviewed-by: David Ahern <dsahern@kernel.org> |
| Signed-off-by: David S. Miller <davem@davemloft.net> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| net/ipv4/fib_frontend.c | 2 ++ |
| 1 file changed, 2 insertions(+) |
| |
| diff --git a/net/ipv4/fib_frontend.c b/net/ipv4/fib_frontend.c |
| index 84bb707bd88d..647bceab56c2 100644 |
| --- a/net/ipv4/fib_frontend.c |
| +++ b/net/ipv4/fib_frontend.c |
| @@ -371,6 +371,8 @@ static int __fib_validate_source(struct sk_buff *skb, __be32 src, __be32 dst, |
| fl4.flowi4_proto = 0; |
| fl4.fl4_sport = 0; |
| fl4.fl4_dport = 0; |
| + } else { |
| + swap(fl4.fl4_sport, fl4.fl4_dport); |
| } |
| |
| if (fib_lookup(net, &fl4, &res, 0)) |
| -- |
| 2.30.2 |
| |