IP Fragments, more

Francois-Xavier Le Bail <[email protected]>
Newsgroups gmane.linux.network.bridge.ebtables.devel
Message-ID <[email protected]>
Thanks Bart,

I think the file ebt_log.c need the same sort of patch.

Cheers,
Francois-Xavier

Selon Bart De Schuymer <[email protected]>:
> You're right, this patch should fix it. Thanks.
>
> Dave, please apply. This is probably a candidate for -stable.
>
> cheers,
> Bart
>
>
> [EBTABLES] Don't match tcp/udp source/destination port for IP fragments
>
> Signed-off-by: Bart De Schuymer <[email protected]>
>
>
> --- linux-2.6.14.2/net/bridge/netfilter/ebt_ip.c.old	2006-01-10
> 19:54:08.000000000 +0100
> +++ linux-2.6.14.2/net/bridge/netfilter/ebt_ip.c	2006-01-10
> 19:59:18.000000000 +0100
> @@ -15,6 +15,7 @@
>  #include <linux/netfilter_bridge/ebtables.h>
>  #include <linux/netfilter_bridge/ebt_ip.h>
>  #include <linux/ip.h>
> +#include <net/ip.h>
>  #include <linux/in.h>
>  #include <linux/module.h>
>
> @@ -51,6 +52,8 @@ static int ebt_filter_ip(const struct sk
>  		if (!(info->bitmask & EBT_IP_DPORT) &&
>  		    !(info->bitmask & EBT_IP_SPORT))
>  			return EBT_MATCH;
> +		if (ntohs(ih->frag_off) & IP_OFFSET)
> +			return EBT_NOMATCH;
>  		pptr = skb_header_pointer(skb, ih->ihl*4,
>  					  sizeof(_ports), &_ports);
>  		if (pptr == NULL)
>
>
>




-------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc. Do you grep through log files
for problems?  Stop!  Download the new AJAX search engine that makes
searching your log files as easy as surfing the  web.  DOWNLOAD SPLUNK!
http://ads.osdn.com/?ad_idv37&alloc_id865&op=click
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.