From: David Miller <davem@davemloft.net>
To: kazunori@miyazawa.org
Cc: usagi-core@linux-ipv6.org, miika@iki.fi, Diego.Beltrami@hiit.fi,
herbert@gondor.apana.org.au, netdev@vger.kernel.org
Subject: Re: (usagi-core 31727) Re: [PATCH][IPSEC][6/7] inter address family ipsec tunnel
Date: Sun, 03 Dec 2006 22:33:36 -0800 (PST) [thread overview]
Message-ID: <20061203.223336.71087901.davem@davemloft.net> (raw)
In-Reply-To: <4573A375.7010100@miyazawa.org>
From: Kazunori MIYAZAWA <kazunori@miyazawa.org>
Date: Mon, 04 Dec 2006 13:26:29 +0900
> If uninitialized ut->family is AF_INET or AF_INET6 by chance
> and the family of outer addresses (ut->saddr) is differnt
> ut->family, it results some garbage in the kernel as you know.
>
> I think it does not results any oops or a segmentation fault
> because xfrm_address always has enough length (16 bytes) to wrong
> access.
>
> From the point of view of security, the policy has garbege
> templates, but the selector is valid and it mangates applying
> IPsec. So it result blocking the traffic.
> Accordingly, I think it falls down to secure side.
Yes, I am beginning to think it is safe too.
prev parent reply other threads:[~2006-12-04 6:33 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2006-11-24 5:39 [PATCH][IPSEC][6/7] inter address family ipsec tunnel Kazunori MIYAZAWA
2006-12-01 1:05 ` David Miller
2006-12-01 5:07 ` Kazunori MIYAZAWA
2006-12-04 1:58 ` David Miller
2006-12-04 2:28 ` David Miller
2006-12-04 2:50 ` Kazunori MIYAZAWA
2006-12-04 3:12 ` David Miller
2006-12-04 3:30 ` Herbert Xu
2006-12-04 4:26 ` (usagi-core 31727) " Kazunori MIYAZAWA
2006-12-04 6:33 ` David Miller [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20061203.223336.71087901.davem@davemloft.net \
--to=davem@davemloft.net \
--cc=Diego.Beltrami@hiit.fi \
--cc=herbert@gondor.apana.org.au \
--cc=kazunori@miyazawa.org \
--cc=miika@iki.fi \
--cc=netdev@vger.kernel.org \
--cc=usagi-core@linux-ipv6.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).