From mboxrd@z Thu Jan 1 00:00:00 1970 From: David Miller Subject: Re: [PATCH] net: check the length of the data before dereferencing it Date: Sun, 01 Apr 2012 23:19:54 -0400 (EDT) Message-ID: <20120401.231954.992963391252108626.davem@davemloft.net> References: <1333336250-4110-1-git-send-email-xiaosuo@gmail.com> Mime-Version: 1.0 Content-Type: Text/Plain; charset=us-ascii Content-Transfer-Encoding: 7bit Cc: kaber@trash.net, pablo@netfilter.org, eric.dumazet@gmail.com, netfilter-devel@vger.kernel.org, netdev@vger.kernel.org To: xiaosuo@gmail.com Return-path: Received: from shards.monkeyblade.net ([198.137.202.13]:47137 "EHLO shards.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1754204Ab2DBDWD (ORCPT ); Sun, 1 Apr 2012 23:22:03 -0400 In-Reply-To: <1333336250-4110-1-git-send-email-xiaosuo@gmail.com> Sender: netfilter-devel-owner@vger.kernel.org List-ID: From: Changli Gao Date: Mon, 2 Apr 2012 11:10:50 +0800 > We should check the length of the data before dereferencing it when parsing > the TCP options. > > Signed-off-by: Changli Gao Proper Subject prefix here would be "tcp: ", not "net: " and maybe adjust the subject line to also mention the specific function being fixed, which in this case would be tcp_parse_options(). So: tcp: Validate length of data before dereference in tcp_parse_options(). and then you can make the commit message just be your signoff.