[PATCH] IPV6: XFRM: Don't use old copy of pointer after pskb_may_pull().
authorYOSHIFUJI Hideaki / \e$B5HF#1QL@\e(B <yoshfuji@linux-ipv6.org>
Wed, 19 Apr 2006 02:14:07 +0000 (11:14 +0900)
committerGreg Kroah-Hartman <gregkh@suse.de>
Mon, 24 Apr 2006 16:56:04 +0000 (09:56 -0700)
[IPV6] XFRM: Don't use old copy of pointer after pskb_may_pull().

Signed-off-by: YOSHIFUJI Hideaki <yoshfuji@linux-ipv6.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
net/ipv6/xfrm6_policy.c

index 91cce8b2d7a5643b523c55b12758756a0d374aee..588922bd926487e5f2df6e1001059d43ff84e175 100644 (file)
@@ -193,7 +193,7 @@ _decode_session6(struct sk_buff *skb, struct flowi *fl)
 {
        u16 offset = sizeof(struct ipv6hdr);
        struct ipv6hdr *hdr = skb->nh.ipv6h;
-       struct ipv6_opt_hdr *exthdr = (struct ipv6_opt_hdr*)(skb->nh.raw + offset);
+       struct ipv6_opt_hdr *exthdr;
        u8 nexthdr = skb->nh.ipv6h->nexthdr;
 
        memset(fl, 0, sizeof(struct flowi));
@@ -201,6 +201,8 @@ _decode_session6(struct sk_buff *skb, struct flowi *fl)
        ipv6_addr_copy(&fl->fl6_src, &hdr->saddr);
 
        while (pskb_may_pull(skb, skb->nh.raw + offset + 1 - skb->data)) {
+               exthdr = (struct ipv6_opt_hdr*)(skb->nh.raw + offset);
+
                switch (nexthdr) {
                case NEXTHDR_ROUTING:
                case NEXTHDR_HOP: