[ 28/42] ipv6/tcp: Stop processing ICMPv6 redirect messages

From: Greg Kroah-Hartman
Date: Mon Apr 29 2013 - 15:36:30 EST

3.8-stable review patch. If anyone has any objections, please let me know.


From: Christoph Paasch <christoph.paasch@xxxxxxxxxxxx>

[ Upstream commit 50a75a8914539c5dcd441c5f54d237a666a426fd ]

Tetja Rediske found that if the host receives an ICMPv6 redirect message
after sending a SYN+ACK, the connection will be reset.

He bisected it down to 093d04d (ipv6: Change skb->data before using
icmpv6_notify() to propagate redirect), but the origin of the bug comes
from ec18d9a26 (ipv6: Add redirect support to all protocol icmp error
handlers.). The bug simply did not trigger prior to 093d04d, because
skb->data did not point to the inner IP header and thus icmpv6_notify
did not call the correct err_handler.

This patch adds the missing "goto out;" in tcp_v6_err. After receiving
an ICMPv6 Redirect, we should not continue processing the ICMP in
tcp_v6_err, as this may trigger the removal of request-socks or setting

Reported-by: Tetja Rediske <tetja@xxxxxxxx>
Signed-off-by: Christoph Paasch <christoph.paasch@xxxxxxxxxxxx>
Acked-by: Eric Dumazet <edumazet@xxxxxxxxxx>
Signed-off-by: David S. Miller <davem@xxxxxxxxxxxxx>
Signed-off-by: Greg Kroah-Hartman <gregkh@xxxxxxxxxxxxxxxxxxx>
net/ipv6/tcp_ipv6.c | 1 +
1 file changed, 1 insertion(+)

--- a/net/ipv6/tcp_ipv6.c
+++ b/net/ipv6/tcp_ipv6.c
@@ -386,6 +386,7 @@ static void tcp_v6_err(struct sk_buff *s

if (dst)
dst->ops->redirect(dst, sk, skb);
+ goto out;

if (type == ICMPV6_PKT_TOOBIG) {

