summaryrefslogtreecommitdiff
path: root/net
diff options
context:
space:
mode:
authorMiao Wang <shankerwangmiao@gmail.com>2021-06-22 12:24:50 +0800
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>2021-07-14 16:59:59 +0200
commitd20d69c405c6788c7431e82f233f2f59a3df25b0 (patch)
tree46eccc86b0f9260d4cd357c9a0a8ec90b818ef77 /net
parentb0f32a899629b12f18b06507ab972bf9dd7a5491 (diff)
downloadlinux-d20d69c405c6788c7431e82f233f2f59a3df25b0.tar.gz
linux-d20d69c405c6788c7431e82f233f2f59a3df25b0.tar.bz2
linux-d20d69c405c6788c7431e82f233f2f59a3df25b0.zip
net/ipv4: swap flow ports when validating source
[ Upstream commit c69f114d09891adfa3e301a35d9e872b8b7b5a50 ] When doing source address validation, the flowi4 struct used for fib_lookup should be in the reverse direction to the given skb. fl4_dport and fl4_sport returned by fib4_rules_early_flow_dissect should thus be swapped. Fixes: 5a847a6e1477 ("net/ipv4: Initialize proto and ports in flow struct") Signed-off-by: Miao Wang <shankerwangmiao@gmail.com> Reviewed-by: David Ahern <dsahern@kernel.org> Signed-off-by: David S. Miller <davem@davemloft.net> Signed-off-by: Sasha Levin <sashal@kernel.org>
Diffstat (limited to 'net')
-rw-r--r--net/ipv4/fib_frontend.c2
1 files changed, 2 insertions, 0 deletions
diff --git a/net/ipv4/fib_frontend.c b/net/ipv4/fib_frontend.c
index 84bb707bd88d..647bceab56c2 100644
--- a/net/ipv4/fib_frontend.c
+++ b/net/ipv4/fib_frontend.c
@@ -371,6 +371,8 @@ static int __fib_validate_source(struct sk_buff *skb, __be32 src, __be32 dst,
fl4.flowi4_proto = 0;
fl4.fl4_sport = 0;
fl4.fl4_dport = 0;
+ } else {
+ swap(fl4.fl4_sport, fl4.fl4_dport);
}
if (fib_lookup(net, &fl4, &res, 0))