Commit bb11386f authored by Pablo Neira Ayuso's avatar Pablo Neira Ayuso Committed by Yang Yingliang
Browse files

netfilter: nft_osf: check for TCP packet before further processing



stable inclusion
from linux-4.19.198
commit 3225cd78880a15928f8930e3de698a6edca63f42

--------------------------------

[ Upstream commit 8f518d43 ]

The osf expression only supports for TCP packets, add a upfront sanity
check to skip packet parsing if this is not a TCP packet.

Fixes: b96af92d ("netfilter: nf_tables: implement Passive OS fingerprint module in nft_osf")
Signed-off-by: default avatarPablo Neira Ayuso <pablo@netfilter.org>
Reported-by: default avatarkernel test robot <lkp@intel.com>
Signed-off-by: default avatarPablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: default avatarSasha Levin <sashal@kernel.org>
Signed-off-by: default avatarYang Yingliang <yangyingliang@huawei.com>
parent f5488e18
Loading
Loading
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please to comment