[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <20190604160305.7bpwsjsjoosj2szt@salvia>
Date: Tue, 4 Jun 2019 18:03:05 +0200
From: Pablo Neira Ayuso <pablo@...filter.org>
To: Guillaume Nault <gnault@...hat.com>
Cc: netdev@...r.kernel.org, netfilter-devel@...r.kernel.org,
Peter Oskolkov <posk@...gle.com>,
Florian Westphal <fw@...len.de>,
"David S. Miller" <davem@...emloft.net>
Subject: Re: [PATCH net] netfilter: ipv6: nf_defrag: fix leakage of unqueued
fragments
On Tue, Jun 04, 2019 at 05:02:21PM +0200, Guillaume Nault wrote:
> On Tue, Jun 04, 2019 at 03:26:05PM +0200, Pablo Neira Ayuso wrote:
> > On Sun, Jun 02, 2019 at 03:13:47PM +0200, Guillaume Nault wrote:
> > > With commit 997dd9647164 ("net: IP6 defrag: use rbtrees in
> > > nf_conntrack_reasm.c"), nf_ct_frag6_reasm() is now called from
> > > nf_ct_frag6_queue(). With this change, nf_ct_frag6_queue() can fail
> > > after the skb has been added to the fragment queue and
> > > nf_ct_frag6_gather() was adapted to handle this case.
> >
> > Applied, thanks.
>
> Thanks. Can you also please queue it for -stable?
As soon as this hits Linus tree, yes.
Powered by blists - more mailing lists