git: d2eeacf7728a - stable/12 - ipfw(8) crashes when ext6hdr option is omitted

Kristof Provost kp at FreeBSD.org
Thu Feb 4 14:23:05 UTC 2021


The branch stable/12 has been updated by kp:

URL: https://cgit.FreeBSD.org/src/commit/?id=d2eeacf7728a04ee04be8a69b2b1bf375ff24994

commit d2eeacf7728a04ee04be8a69b2b1bf375ff24994
Author:     Evgeniy Khramtsov <2khramtsov at gmail.com>
AuthorDate: 2021-02-01 19:03:57 +0000
Commit:     Kristof Provost <kp at FreeBSD.org>
CommitDate: 2021-02-04 08:13:46 +0000

    ipfw(8) crashes when ext6hdr option is omitted
    
    Verify that the option is passed, error out if it's not.
    The problem can be trivially triggered with `ipfw add allow ext6hdr`.
    
    PR:             253169
    Reviewed by:    kp@
    MFC after:      3 days
    Differential Revision:  https://reviews.freebsd.org/D28447
    
    (cherry picked from commit 682c31db4ecfb8fc6cac0e8ad4945c03379ea3d1)
---
 sbin/ipfw/ipfw2.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/sbin/ipfw/ipfw2.c b/sbin/ipfw/ipfw2.c
index 85347b1add03..30a4da92343f 100644
--- a/sbin/ipfw/ipfw2.c
+++ b/sbin/ipfw/ipfw2.c
@@ -4961,6 +4961,7 @@ read_options:
 			break;
 
 		case TOK_EXT6HDR:
+			NEED1("missing extension header");
 			fill_ext6hdr( cmd, *av );
 			av++;
 			break;


More information about the dev-commits-src-all mailing list