Files
linux/net/dccp
Eric Dumazet 1a15519fdc net/dccp: fix use-after-free in dccp_invalid_packet
[ Upstream commit 648f0c28df ]

pskb_may_pull() can reallocate skb->head, we need to reload dh pointer
in dccp_invalid_packet() or risk use after free.

Bug found by Andrey Konovalov using syzkaller.

Signed-off-by: Eric Dumazet <edumazet@google.com>
Reported-by: Andrey Konovalov <andreyknvl@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2016-12-10 19:07:24 +01:00
..
2014-02-16 23:45:00 -05:00
2014-11-18 15:26:31 -05:00
2014-11-18 15:26:32 -05:00
2014-01-04 20:18:49 -05:00
2015-11-01 17:01:16 -05:00