Project

General

Profile

Actions

Bug #2118

closed

defrag - overlap issue in linux policy

Added by Jason Ish almost 7 years ago. Updated almost 7 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

When two fragment overlap one another, suricata seems to privilege data from the fragment with the lower offset, when the linux convention seems to keep the first (in time) data received.

This appears to be an edge case not handled by the existing unit tests.

Reported by Jérémy Beaume.

Actions #1

Updated by Jason Ish almost 7 years ago

Issue has been fixed in git master:
https://github.com/inliniac/suricata/pull/2648

Actions #2

Updated by Jason Ish almost 7 years ago

  • Status changed from Assigned to Closed
Actions

Also available in: Atom PDF