From 0cb88b6ff054ccfa30e0fd7f7b42ee9f088db432 Mon Sep 17 00:00:00 2001 From: Richard Guy Briggs Date: Tue, 2 May 2017 10:16:04 -0400 Subject: [PATCH] netfilter: use consistent ipv4 network offset in xt_AUDIT Even though the skb->data pointer has been moved from the link layer header to the network layer header, use the same method to calculate the offset in ipv4 and ipv6 routines. Signed-off-by: Richard Guy Briggs [PM: munged subject line] Signed-off-by: Paul Moore --- net/netfilter/xt_AUDIT.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/net/netfilter/xt_AUDIT.c b/net/netfilter/xt_AUDIT.c index 19247a17e511..5181f69ec9bf 100644 --- a/net/netfilter/xt_AUDIT.c +++ b/net/netfilter/xt_AUDIT.c @@ -76,7 +76,7 @@ static void audit_ip4(struct audit_buffer *ab, struct sk_buff *skb) struct iphdr _iph; const struct iphdr *ih; - ih = skb_header_pointer(skb, 0, sizeof(_iph), &_iph); + ih = skb_header_pointer(skb, skb_network_offset(skb), sizeof(_iph), &_iph); if (!ih) { audit_log_format(ab, " truncated=1"); return; -- 2.20.1