]> git.kernelconcepts.de Git - karo-tx-linux.git/commit
[IPSEC]: Reject packets within replay window but outside the bit mask
authorHerbert Xu <herbert@gondor.apana.org.au>
Fri, 13 Apr 2007 19:32:53 +0000 (21:32 +0200)
committerAdrian Bunk <bunk@stusta.de>
Fri, 13 Apr 2007 20:58:27 +0000 (22:58 +0200)
commitef846bc01da49cf63d289e97139bef5181e75229
tree0ec4d20b4d2705ac0d8a1e52566748f93d7e8cfb
parent19a0662baeb7f783d345ebdfe3048b834582b294
[IPSEC]: Reject packets within replay window but outside the bit mask

Up until this point we've accepted replay window settings greater than
32 but our bit mask can only accomodate 32 packets.  Thus any packet
with a sequence number within the window but outside the bit mask would
be accepted.

This patch causes those packets to be rejected instead.

Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Adrian Bunk <bunk@stusta.de>
net/xfrm/xfrm_state.c