浏览代码

netfilter: nft_reject_bridge: fix skb allocation size in nft_reject_br_send_v6_unreach

In order to allocate icmpv6 skb, sizeof(struct ipv6hdr) should be used.

Signed-off-by: Taehee Yoo <ap420073@gmail.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Taehee Yoo 7 年之前
父节点
当前提交
0cafa3926f
共有 1 个文件被更改,包括 1 次插入1 次删除
  1. 1 1
      net/bridge/netfilter/nft_reject_bridge.c

+ 1 - 1
net/bridge/netfilter/nft_reject_bridge.c

@@ -261,7 +261,7 @@ static void nft_reject_br_send_v6_unreach(struct net *net,
 	if (!reject6_br_csum_ok(oldskb, hook))
 	if (!reject6_br_csum_ok(oldskb, hook))
 		return;
 		return;
 
 
-	nskb = alloc_skb(sizeof(struct iphdr) + sizeof(struct icmp6hdr) +
+	nskb = alloc_skb(sizeof(struct ipv6hdr) + sizeof(struct icmp6hdr) +
 			 LL_MAX_HEADER + len, GFP_ATOMIC);
 			 LL_MAX_HEADER + len, GFP_ATOMIC);
 	if (!nskb)
 	if (!nskb)
 		return;
 		return;