aboutsummaryrefslogtreecommitdiff
path: root/net/core
diff options
context:
space:
mode:
authorPeter Oskolkov2018-08-02 23:34:37 +0000
committerDavid S. Miller2018-08-05 17:16:46 -0700
commit7969e5c40dfd04799d4341f1b7cd266b6e47f227 (patch)
tree167103e66b8f8ebf96bf4ca7644c3e0f7b3bca10 /net/core
parentcfb4099fb4c101dad283a163c9525240ef4a1a99 (diff)
ip: discard IPv4 datagrams with overlapping segments.
This behavior is required in IPv6, and there is little need to tolerate overlapping fragments in IPv4. This change simplifies the code and eliminates potential DDoS attack vectors. Tested: ran ip_defrag selftest (not yet available uptream). Suggested-by: David S. Miller <davem@davemloft.net> Signed-off-by: Peter Oskolkov <posk@google.com> Signed-off-by: Eric Dumazet <edumazet@google.com> Cc: Florian Westphal <fw@strlen.de> Acked-by: Stephen Hemminger <stephen@networkplumber.org> Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to 'net/core')
0 files changed, 0 insertions, 0 deletions