netdev
[Top] [All Lists]

Re: [PATCH]: invaild TCP/UDP matching when ipv6 extension header exists

To: Yasuyuki Kozakai <yasuyuki.kozakai@xxxxxxxxxxxxx>
Subject: Re: [PATCH]: invaild TCP/UDP matching when ipv6 extension header exists
From: "David S. Miller" <davem@xxxxxxxxxx>
Date: Thu, 26 Feb 2004 12:37:32 -0800
Cc: netfilter-devel@xxxxxxxxxxxxxxxxxxx, netdev@xxxxxxxxxxx, usagi-core@xxxxxxxxxxxxxx
In-reply-to: <200402260406.NAA16034@toshiba.co.jp>
References: <200401310649.PAA00050@toshiba.co.jp> <200402200612.PAA12001@toshiba.co.jp> <20040220093158.3c12ea9a.davem@redhat.com> <200402260406.NAA16034@toshiba.co.jp>
Sender: netdev-bounce@xxxxxxxxxxx
On Thu, 26 Feb 2004 13:05:50 +0900 (JST)
Yasuyuki Kozakai <yasuyuki.kozakai@xxxxxxxxxxxxx> wrote:

> This patch is for linux 2.4.26-pre1 .
> 
> Summery:
> tcp_match() and udp_match() in ip6tables.c assume that previous header
> of TCP/UDP header is IPv6 Header. So, for example, 1st of fragmented UDP
> packet, AHed packets can't correctly match the rules which use
> "--sport" and so on.

Also applied, thank you.

<Prev in Thread] Current Thread [Next in Thread>