From mboxrd@z Thu Jan 1 00:00:00 1970 From: David Miller Subject: Re: [PATCHv2 2/2] bridge: multicast: enable snooping on general queries only Date: Tue, 11 Mar 2014 23:23:31 -0400 (EDT) Message-ID: <20140311.232331.953854418721439734.davem@davemloft.net> References: <1394486725-4992-1-git-send-email-linus.luessing@web.de> <1394486725-4992-2-git-send-email-linus.luessing@web.de> Mime-Version: 1.0 Content-Type: Text/Plain; charset=iso-8859-1 Content-Transfer-Encoding: quoted-printable Cc: netdev@vger.kernel.org, fwestpha@redhat.com, bridge@lists.linux-foundation.org, linux-kernel@vger.kernel.org, stephen@networkplumber.org, jstancek@redhat.com To: linus.luessing@web.de Return-path: In-Reply-To: <1394486725-4992-2-git-send-email-linus.luessing@web.de> List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: bridge-bounces@lists.linux-foundation.org Errors-To: bridge-bounces@lists.linux-foundation.org List-Id: netdev.vger.kernel.org From: Linus L=FCssing Date: Mon, 10 Mar 2014 22:25:25 +0100 > Without this check someone could easily create a denial of service > by injecting multicast-specific queries to enable the bridge > snooping part if no real querier issuing periodic general queries > is present on the link which would result in the bridge wrongly > shutting down ports for multicast traffic as the bridge did not learn= > about these listeners. > = > With this patch the snooping code is enabled upon receiving valid, > general queries only. > = > Signed-off-by: Linus L=FCssing Applied.