Eric Dumazet 648f0c28df net/dccp: fix use-after-free in dccp_invalid_packet
pskb_may_pull() can reallocate skb->head, we need to reload dh pointer
in dccp_invalid_packet() or risk use after free.

Bug found by Andrey Konovalov using syzkaller.

Signed-off-by: Eric Dumazet <edumazet@google.com>
Reported-by: Andrey Konovalov <andreyknvl@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-11-29 20:37:26 -05:00
..
2014-02-16 23:45:00 -05:00
2016-04-27 22:48:25 -04:00
2014-11-18 15:26:31 -05:00
2016-04-27 22:48:22 -04:00
2015-11-30 14:47:33 -05:00
2015-11-01 17:01:16 -05:00
2016-04-27 22:48:24 -04:00