mirror of
https://github.com/haproxy/haproxy.git
synced 2026-02-26 03:13:35 -05:00
MINOR: quic: Drop Initial packets with wrong ODCID
According to the RFC 9000, the client ODCID must have a minimal length of 8 bytes.
This commit is contained in:
parent
629cbdf5cc
commit
dc36404c36
2 changed files with 7 additions and 0 deletions
|
|
@ -62,6 +62,8 @@ typedef unsigned long long ull;
|
|||
/* Common definitions for short and long QUIC packet headers. */
|
||||
/* QUIC connection ID maximum length for version 1. */
|
||||
#define QUIC_CID_MAXLEN 20 /* bytes */
|
||||
/* QUIC original destination connection ID minial length */
|
||||
#define QUIC_ODCID_MINLEN 8 /* bytes */
|
||||
/*
|
||||
* All QUIC packets with long headers are made of at least (in bytes):
|
||||
* flags(1), version(4), DCID length(1), DCID(0..20), SCID length(1), SCID(0..20)
|
||||
|
|
|
|||
|
|
@ -4308,6 +4308,11 @@ static ssize_t qc_lstnr_pkt_rcv(unsigned char *buf, const unsigned char *end,
|
|||
goto err;
|
||||
}
|
||||
|
||||
if (pkt->dcid.len < QUIC_ODCID_MINLEN) {
|
||||
TRACE_PROTO("dropped packet", QUIC_EV_CONN_LPKT);
|
||||
goto err;
|
||||
}
|
||||
|
||||
pkt->saddr = dgram->saddr;
|
||||
ipv4 = dgram->saddr.ss_family == AF_INET;
|
||||
qc = qc_new_conn(pkt->version, ipv4,
|
||||
|
|
|
|||
Loading…
Reference in a new issue