tech-net archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: NPF: TCP options



On Thu, Mar 08, 2018 at 09:15:40AM +0100, Maxime Villard wrote:
> In NPF we don't check the length of the TCPOPT_MAXSEG and TCPOPT_WINDOW
> options. That's a problem, if the length is bogus we should ignore these
> options, just like the kernel does in tcp_dooptions().

I don't think so. A firewall should drop bogus stuff.

Joerg


Home | Main Index | Thread Index | Old Index