+2
−2
Loading
Ensure the entire TLV header is linearized before access by adding sizeof(struct hsr_sup_tlv) to the pskb_may_pull() calls. Without this, a truncated frame could cause an out-of-bounds access. Fixes: eafaa88b ("net: hsr: Add support for redbox supervision frames") Signed-off-by:Luka Gejak <luka.gejak@linux.dev> Reviewed-by:
Fernando Fernandez Mancera <fmancera@suse.de> Link: https://patch.msgid.link/20260523130330.61880-1-luka.gejak@linux.dev Signed-off-by:
Jakub Kicinski <kuba@kernel.org>