commit | 35c30d3efdfb7d06f978cdb711cb27bc280dcbe8 | [log] [tgz] |
---|---|---|
author | Stefan Hajnoczi <stefanha@redhat.com> | Wed Jul 15 17:39:29 2015 +0100 |
committer | Michael Roth <mdroth@linux.vnet.ibm.com> | Tue Aug 04 12:34:00 2015 -0500 |
tree | 94e2a6609fc00838372f0085e1907fe0f7fa590f | |
parent | f4c861fd68838649e81e0f9a6d75b154fda76440 [diff] |
rtl8139: check TCP Data Offset field (CVE-2015-5165) The TCP Data Offset field contains the length of the header. Make sure it is valid and does not exceed the IP data length. Reported-by: 朱东海(启路) <donghai.zdh@alibaba-inc.com> Reviewed-by: Jason Wang <jasowang@redhat.com> Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com> (cherry picked from commit 8357946b15f0a31f73dd691b7da95f29318ed310) Signed-off-by: Michael Roth <mdroth@linux.vnet.ibm.com>