netfilter: nf_tables_ipv6: consider network offset in netdev/egress validation
authorPablo Neira Ayuso <pablo@netfilter.org>
Mon, 26 Aug 2024 13:03:23 +0000 (15:03 +0200)
committerPablo Neira Ayuso <pablo@netfilter.org>
Tue, 27 Aug 2024 16:11:56 +0000 (18:11 +0200)
commit70c261d500951cf3ea0fcf32651aab9a65a91471
tree83e88e84dd109558d1d0bbfb8f95022df6a7dfcb
parent5fd0628918977a0afdc2e6bc562d8751b5d3b8c5
netfilter: nf_tables_ipv6: consider network offset in netdev/egress validation

From netdev/egress, skb->len can include the ethernet header, therefore,
subtract network offset from skb->len when validating IPv6 packet length.

Fixes: 42df6e1d221d ("netfilter: Introduce egress hook")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
include/net/netfilter/nf_tables_ipv6.h