icmp: Fix a data-race around sysctl_icmp_echo_ignore_broadcasts.
While reading sysctl_icmp_echo_ignore_broadcasts, it can be changed
concurrently. Thus, we need to add READ_ONCE() to its reader.
Fixes: 1da177e4c3
("Linux-2.6.12-rc2")
Signed-off-by: Kuniyuki Iwashima <kuniyu@amazon.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
This commit is contained in:
parent
4a2f7083cc
commit
66484bb98e
@ -1249,7 +1249,7 @@ int icmp_rcv(struct sk_buff *skb)
|
||||
*/
|
||||
if ((icmph->type == ICMP_ECHO ||
|
||||
icmph->type == ICMP_TIMESTAMP) &&
|
||||
net->ipv4.sysctl_icmp_echo_ignore_broadcasts) {
|
||||
READ_ONCE(net->ipv4.sysctl_icmp_echo_ignore_broadcasts)) {
|
||||
reason = SKB_DROP_REASON_INVALID_PROTO;
|
||||
goto error;
|
||||
}
|
||||
|
@ -617,6 +617,8 @@ static struct ctl_table ipv4_net_table[] = {
|
||||
.maxlen = sizeof(u8),
|
||||
.mode = 0644,
|
||||
.proc_handler = proc_dou8vec_minmax,
|
||||
.extra1 = SYSCTL_ZERO,
|
||||
.extra2 = SYSCTL_ONE
|
||||
},
|
||||
{
|
||||
.procname = "icmp_ignore_bogus_error_responses",
|
||||
|
Loading…
Reference in New Issue
Block a user