xfrm: Fix replay size checking on async events
authorSteffen Klassert <steffen.klassert@secunet.com>
Mon, 9 Sep 2013 07:39:01 +0000 (09:39 +0200)
committerSteffen Klassert <steffen.klassert@secunet.com>
Mon, 16 Sep 2013 07:39:37 +0000 (09:39 +0200)
commit4479ff76c43607b680f9349128d8493228b49dce
tree5144879a8baaa977847276d0c4758cd8f2735bce
parent73a695f8572e4c46a2aecdbb63f26f36a43e6873
xfrm: Fix replay size checking on async events

We pass the wrong netlink attribute to xfrm_replay_verify_len().
It should be XFRMA_REPLAY_ESN_VAL and not XFRMA_REPLAY_VAL as
we currently doing. This causes memory corruptions if the
replay esn attribute has incorrect length. Fix this by passing
the right attribute to xfrm_replay_verify_len().

Reported-by: Michael Rossberg <michael.rossberg@tu-ilmenau.de>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
net/xfrm/xfrm_user.c