netfilter: xtables: avoid BUG_ON
authorFlorian Westphal <fw@strlen.de>
Tue, 4 Sep 2018 14:01:57 +0000 (16:01 +0200)
committerPablo Neira Ayuso <pablo@netfilter.org>
Mon, 17 Sep 2018 14:11:12 +0000 (16:11 +0200)
commit70c0eb1ca016f7b6be6cd2a47efc4c701ce4488f
treebd63a56577665026aa8f24458f734dcced723ace
parentfa5950e498e7face21a1761f327e6c1152f778c3
netfilter: xtables: avoid BUG_ON

I see no reason for them, label or timer cannot be NULL, and if they
were, we'll crash with null deref anyway.

For skb_header_pointer failure, just set hotdrop to true and toss
such packet.

Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
net/ipv6/netfilter/ip6t_ipv6header.c
net/ipv6/netfilter/ip6t_rt.c
net/netfilter/xt_IDLETIMER.c
net/netfilter/xt_SECMARK.c