]> git.baikalelectronics.ru Git - kernel.git/commit
[NETFILTER]: ip6t_mh: drop piggyback payload packet on MH packets
authorMasahide NAKAMURA <nakam@linux-ipv6.org>
Mon, 12 Feb 2007 19:16:17 +0000 (11:16 -0800)
committerDavid S. Miller <davem@davemloft.net>
Mon, 12 Feb 2007 19:16:17 +0000 (11:16 -0800)
commit32950f55b940ccd68fed0a8478f93999756607c0
tree9c3ec935238bc2850435230b099c12dfc216f1dc
parent14f60f20bb5112d6d762753c595180ce0eede38a
[NETFILTER]: ip6t_mh: drop piggyback payload packet on MH packets

Regarding RFC3775, MH payload proto field should be IPPROTO_NONE. Otherwise
it must be discarded (and the receiver should send ICMP error).

We assume filter should drop such piggyback everytime to disallow slipping
through firewall rules, even the final receiver will discard it.

Signed-off-by: Masahide NAKAMURA <nakam@linux-ipv6.org>
Signed-off-by: Patrick McHardy <kaber@trash.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
net/ipv6/netfilter/ip6t_mh.c