netfilter: nft_exthdr: break evaluation if setting TCP option fails
authorPablo Neira Ayuso <pablo@netfilter.org>
Tue, 30 Nov 2021 10:34:04 +0000 (11:34 +0100)
committerPablo Neira Ayuso <pablo@netfilter.org>
Wed, 8 Dec 2021 00:05:55 +0000 (01:05 +0100)
commit962e5a40358787105f126ab1dc01604da3d169e9
treeb798c33b9485823c743f05c8039edb1f8272f6d3
parent0de53b0ffb5b22b52c1e0bd4d9e18cbbce5801d0
netfilter: nft_exthdr: break evaluation if setting TCP option fails

Break rule evaluation on malformed TCP options.

Fixes: 99d1712bc41c ("netfilter: exthdr: tcp option set support")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
net/netfilter/nft_exthdr.c