From: Sarveshwar Bandi Date: Wed, 10 Oct 2012 01:15:01 +0000 (+0000) Subject: bridge: Pull ip header into skb->data before looking into ip header. X-Git-Tag: v3.2.39~4 X-Git-Url: https://git.karo-electronics.de/?a=commitdiff_plain;h=335c3391c34f5a607ca63d606f9b2d9f747bab4a;p=karo-tx-linux.git bridge: Pull ip header into skb->data before looking into ip header. [ Upstream commit 6caab7b0544e83e6c160b5e80f5a4a7dd69545c7 ] If lower layer driver leaves the ip header in the skb fragment, it needs to be first pulled into skb->data before inspecting ip header length or ip version number. Signed-off-by: Sarveshwar Bandi Signed-off-by: David S. Miller Signed-off-by: Ben Hutchings --- diff --git a/net/bridge/br_netfilter.c b/net/bridge/br_netfilter.c index 577ea5df8282..7c1745d3b4b6 100644 --- a/net/bridge/br_netfilter.c +++ b/net/bridge/br_netfilter.c @@ -245,6 +245,9 @@ static int br_parse_ip_options(struct sk_buff *skb) struct net_device *dev = skb->dev; u32 len; + if (!pskb_may_pull(skb, sizeof(struct iphdr))) + goto inhdr_error; + iph = ip_hdr(skb); opt = &(IPCB(skb)->opt);