Skip to content
Commit 49f817d7 authored by Lin Zhang's avatar Lin Zhang Committed by Pablo Neira Ayuso
Browse files

netfilter: SYNPROXY: skip non-tcp packet in {ipv4, ipv6}_synproxy_hook



In function {ipv4,ipv6}_synproxy_hook we expect a normal tcp packet, but
the real server maybe reply an icmp error packet related to the exist
tcp conntrack, so we will access wrong tcp data.

Fix it by checking for the protocol field and only process tcp traffic.

Signed-off-by: default avatarLin Zhang <xiaolou4617@gmail.com>
Signed-off-by: default avatarPablo Neira Ayuso <pablo@netfilter.org>
parent e466af75
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment