diff options
| author | D.S. Ljungmark <ljungmark@modio.se> | 2016-07-11 16:38:14 -0700 |
|---|---|---|
| committer | Ariel Yin <ayin@google.com> | 2016-07-18 21:24:21 +0000 |
| commit | 58af86ce1dd3a0f3560fa26151caca42e54e804c (patch) | |
| tree | d079814c62cf1a037f1c472fc02b261673b33af2 /net/unix/af_unix.c | |
| parent | a59e0e672f95164a1661262295b39270834d4391 (diff) | |
UPSTREAM: ipv6: Don't reduce hop limit for an interface
(cherry pick from commit 6fd99094de2b83d1d4c8457f2c83483b2828e75a)
A local route may have a lower hop_limit set than global routes do.
RFC 3756, Section 4.2.7, "Parameter Spoofing"
> 1. The attacker includes a Current Hop Limit of one or another
> small
> number which the attacker knows will cause legitimate packets to
> be dropped before they reach their destination.
> As an example, one possible approach to mitigate this threat is to
> ignore very small hop limits. The nodes could implement a
> configurable minimum hop limit, and ignore attempts to set it below
> said limit.
Signed-off-by: D.S. Ljungmark <ljungmark@modio.se>
Acked-by: Hannes Frederic Sowa <hannes@stressinduktion.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Change-Id: I24ee5723e4bcb3fbdbf4308531ab58e9ff215e82
Bug: 29409847
Diffstat (limited to 'net/unix/af_unix.c')
0 files changed, 0 insertions, 0 deletions
