net: ipvs: sctp: add missing verdict assignments in sctp_conn_schedule
If skb_header_pointer() fails, we need to assign a verdict, that is NF_DROP in this case, otherwise, we would leave the verdict from conn_schedule() uninitialized when returning. Signed-off-by: Daniel Borkmann <dborkman@redhat.com> Acked-by: Jesper Dangaard Brouer <brouer@redhat.com> Acked-by: Neil Horman <nhorman@tuxdriver.com> Acked-by: Julian Anastasov <ja@ssi.bg> Signed-off-by: Simon Horman <horms@verge.net.au>
This commit is contained in:
committed by
Simon Horman
parent
6b8dbcf2c4
commit
6e7cd27c0f
@@ -20,13 +20,18 @@ sctp_conn_schedule(int af, struct sk_buff *skb, struct ip_vs_proto_data *pd,
|
|||||||
sctp_sctphdr_t *sh, _sctph;
|
sctp_sctphdr_t *sh, _sctph;
|
||||||
|
|
||||||
sh = skb_header_pointer(skb, iph->len, sizeof(_sctph), &_sctph);
|
sh = skb_header_pointer(skb, iph->len, sizeof(_sctph), &_sctph);
|
||||||
if (sh == NULL)
|
if (sh == NULL) {
|
||||||
|
*verdict = NF_DROP;
|
||||||
return 0;
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
sch = skb_header_pointer(skb, iph->len + sizeof(sctp_sctphdr_t),
|
sch = skb_header_pointer(skb, iph->len + sizeof(sctp_sctphdr_t),
|
||||||
sizeof(_schunkh), &_schunkh);
|
sizeof(_schunkh), &_schunkh);
|
||||||
if (sch == NULL)
|
if (sch == NULL) {
|
||||||
|
*verdict = NF_DROP;
|
||||||
return 0;
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
net = skb_net(skb);
|
net = skb_net(skb);
|
||||||
ipvs = net_ipvs(net);
|
ipvs = net_ipvs(net);
|
||||||
rcu_read_lock();
|
rcu_read_lock();
|
||||||
|
Reference in New Issue
Block a user