Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 6e7cd27c authored by Daniel Borkmann's avatar Daniel Borkmann Committed by Simon Horman
Browse files

net: ipvs: sctp: add missing verdict assignments in sctp_conn_schedule



If skb_header_pointer() fails, we need to assign a verdict, that is
NF_DROP in this case, otherwise, we would leave the verdict from
conn_schedule() uninitialized when returning.

Signed-off-by: default avatarDaniel Borkmann <dborkman@redhat.com>
Acked-by: default avatarJesper Dangaard Brouer <brouer@redhat.com>
Acked-by: default avatarNeil Horman <nhorman@tuxdriver.com>
Acked-by: default avatarJulian Anastasov <ja@ssi.bg>
Signed-off-by: default avatarSimon Horman <horms@verge.net.au>
parent 6b8dbcf2
Loading
Loading
Loading
Loading
+7 −2
Original line number Diff line number Diff line
@@ -20,13 +20,18 @@ sctp_conn_schedule(int af, struct sk_buff *skb, struct ip_vs_proto_data *pd,
	sctp_sctphdr_t *sh, _sctph;

	sh = skb_header_pointer(skb, iph->len, sizeof(_sctph), &_sctph);
	if (sh == NULL)
	if (sh == NULL) {
		*verdict = NF_DROP;
		return 0;
	}

	sch = skb_header_pointer(skb, iph->len + sizeof(sctp_sctphdr_t),
				 sizeof(_schunkh), &_schunkh);
	if (sch == NULL)
	if (sch == NULL) {
		*verdict = NF_DROP;
		return 0;
	}

	net = skb_net(skb);
	ipvs = net_ipvs(net);
	rcu_read_lock();