netfilter: xt_qtaguid: do not look at TCP_TIME_WAIT socket

It is possible that skb->sk may be a TCP_TIME_WAIT socket,
in which case many of the fields will not be valid. Thanks
to Eric Dumazet <edumazet@google.com> for pointing out this
issue and the fix.

http://article.gmane.org/gmane.linux.ports.arm.msm/3400

Change-Id: I1fa955df16f8919ec243d55e6131efb335a7871c
Signed-off-by: Steve Muckle <smuckle@codeaurora.org>
This commit is contained in:
Steve Muckle
2013-02-14 10:49:23 -08:00
committed by Jay Chokshi
parent fdb639de0e
commit 16e940bc5e
+2
View File
@@ -1773,6 +1773,8 @@ static bool qtaguid_mt(const struct sk_buff *skb, struct xt_action_param *par)
}
sk = skb->sk;
if (sk && sk->sk_state == TCP_TIME_WAIT)
sk = NULL;
if (sk == NULL) {
/*
* A missing sk->sk_socket happens when packets are in-flight