batman-adv: fix wrong dhcp option list browsing
Commit Message
In is_type_dhcprequest(), while parsing a DHCP message, if the entry we found in
the option list is neither a padding nor the dhcp-type, we have to ignore it and
jump as many bytes as its length + 1. The "+ 1" byte is given by the subtype
field itself that has to be jumped too.
Reported-by: Marek Lindner <lindner_marek@yahoo.de>
Signed-off-by: Antonio Quartulli <ordex@autistici.org>
---
gateway_client.c | 6 +++---
1 files changed, 3 insertions(+), 3 deletions(-)
Comments
On Monday, February 27, 2012 18:29:53 Antonio Quartulli wrote:
> In is_type_dhcprequest(), while parsing a DHCP message, if the entry we
> found in the option list is neither a padding nor the dhcp-type, we have
> to ignore it and jump as many bytes as its length + 1. The "+ 1" byte is
> given by the subtype field itself that has to be jumped too.
Applied in revision 459c4e4.
Thanks,
Marek
@@ -563,10 +563,10 @@ static bool is_type_dhcprequest(struct sk_buff *skb, int header_len)
p++;
/* ...and then we jump over the data */
- if (pkt_len < *p)
+ if (pkt_len < 1 + (*p))
goto out;
- pkt_len -= *p;
- p += (*p);
+ pkt_len -= 1 + (*p);
+ p += 1 + (*p);
}
}
out: