Re: [PATCH net] ipv6: dccp: fix out of bound access in dccp_v6_err()

2016-11-03 Thread David Miller
From: Eric Dumazet Date: Wed, 02 Nov 2016 20:30:48 -0700 > From: Eric Dumazet > > dccp_v6_err() does not use pskb_may_pull() and might access garbage. > > We only need 4 bytes at the beginning of the DCCP header, like TCP, > so the 8 bytes pulled in icmpv6_notify() are more than enough. > > S

[PATCH net] ipv6: dccp: fix out of bound access in dccp_v6_err()

2016-11-02 Thread Eric Dumazet
From: Eric Dumazet dccp_v6_err() does not use pskb_may_pull() and might access garbage. We only need 4 bytes at the beginning of the DCCP header, like TCP, so the 8 bytes pulled in icmpv6_notify() are more than enough. Signed-off-by: Eric Dumazet --- net/dccp/ipv6.c | 15 --- 1