Skip to content

Commit 9e2dcf7

Browse files
committed
netfilter: nf_conntrack_reasm: properly handle packets fragmented into a single fragment
When an ICMPV6_PKT_TOOBIG message is received with a MTU below 1280, all further packets include a fragment header. Unlike regular defragmentation, conntrack also needs to "reassemble" those fragments in order to obtain a packet without the fragment header for connection tracking. Currently nf_conntrack_reasm checks whether a fragment has either IP6_MF set or an offset != 0, which makes it ignore those fragments. Remove the invalid check and make reassembly handle fragment queues containing only a single fragment. Reported-and-tested-by: Ulrich Weber <uweber@astaro.com> Signed-off-by: Patrick McHardy <kaber@trash.net>
1 parent 64507fd commit 9e2dcf7

File tree

1 file changed

+1
-7
lines changed

1 file changed

+1
-7
lines changed

Diff for: net/ipv6/netfilter/nf_conntrack_reasm.c

+1-7
Original file line numberDiff line numberDiff line change
@@ -469,7 +469,7 @@ nf_ct_frag6_reasm(struct nf_ct_frag6_queue *fq, struct net_device *dev)
469469

470470
/* all original skbs are linked into the NFCT_FRAG6_CB(head).orig */
471471
fp = skb_shinfo(head)->frag_list;
472-
if (NFCT_FRAG6_CB(fp)->orig == NULL)
472+
if (fp && NFCT_FRAG6_CB(fp)->orig == NULL)
473473
/* at above code, head skb is divided into two skbs. */
474474
fp = fp->next;
475475

@@ -595,12 +595,6 @@ struct sk_buff *nf_ct_frag6_gather(struct sk_buff *skb, u32 user)
595595
hdr = ipv6_hdr(clone);
596596
fhdr = (struct frag_hdr *)skb_transport_header(clone);
597597

598-
if (!(fhdr->frag_off & htons(0xFFF9))) {
599-
pr_debug("Invalid fragment offset\n");
600-
/* It is not a fragmented frame */
601-
goto ret_orig;
602-
}
603-
604598
if (atomic_read(&nf_init_frags.mem) > nf_init_frags.high_thresh)
605599
nf_ct_frag6_evictor();
606600

0 commit comments

Comments
 (0)