summaryrefslogtreecommitdiff
path: root/net/ipv4/ip_tunnel.c
diff options
context:
space:
mode:
authorThomas Graf <tgraf@suug.ch>2014-12-16 21:05:21 +0100
committerDavid S. Miller <davem@davemloft.net>2014-12-16 15:20:41 -0500
commitf1fb521f7d94c35e278d76a9198f078223f26799 (patch)
tree8c2c239aa92c0a1cbe8256ec70635c265f3a3285 /net/ipv4/ip_tunnel.c
parentbb1553c800227f33063fe96561af881619447b83 (diff)
downloadlinux-rpi-f1fb521f7d94c35e278d76a9198f078223f26799.tar.gz
linux-rpi-f1fb521f7d94c35e278d76a9198f078223f26799.tar.bz2
linux-rpi-f1fb521f7d94c35e278d76a9198f078223f26799.zip
ip_tunnel: Add missing validation of encap type to ip_tunnel_encap_setup()
The encap->type comes straight from Netlink. Validate it against max supported encap types just like ip_encap_hlen() already does. Fixes: a8c5f9 ("ip_tunnel: Ops registration for secondary encap (fou, gue)") Signed-off-by: Thomas Graf <tgraf@suug.ch> Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to 'net/ipv4/ip_tunnel.c')
-rw-r--r--net/ipv4/ip_tunnel.c3
1 files changed, 3 insertions, 0 deletions
diff --git a/net/ipv4/ip_tunnel.c b/net/ipv4/ip_tunnel.c
index 2f498f87e3d8..d3e447936720 100644
--- a/net/ipv4/ip_tunnel.c
+++ b/net/ipv4/ip_tunnel.c
@@ -573,6 +573,9 @@ int ip_tunnel_encap(struct sk_buff *skb, struct ip_tunnel *t,
if (t->encap.type == TUNNEL_ENCAP_NONE)
return 0;
+ if (t->encap.type >= MAX_IPTUN_ENCAP_OPS)
+ return -EINVAL;
+
rcu_read_lock();
ops = rcu_dereference(iptun_encaps[t->encap.type]);
if (likely(ops && ops->build_header))