summaryrefslogtreecommitdiffstats
path: root/Documentation/powerpc/booting.rst
diff options
context:
space:
mode:
authorEric Dumazet <edumazet@google.com>2022-01-27 02:10:22 +0100
committerJakub Kicinski <kuba@kernel.org>2022-01-27 17:37:02 +0100
commit23f57406b82de51809d5812afd96f210f8b627f3 (patch)
tree21e7e8d8dc4d9bac3afb75db6ea66f8aed7a1226 /Documentation/powerpc/booting.rst
parentipv4: tcp: send zero IPID in SYNACK messages (diff)
downloadlinux-23f57406b82de51809d5812afd96f210f8b627f3.tar.xz
linux-23f57406b82de51809d5812afd96f210f8b627f3.zip
ipv4: avoid using shared IP generator for connected sockets
ip_select_ident_segs() has been very conservative about using the connected socket private generator only for packets with IP_DF set, claiming it was needed for some VJ compression implementations. As mentioned in this referenced document, this can be abused. (Ref: Off-Path TCP Exploits of the Mixed IPID Assignment) Before switching to pure random IPID generation and possibly hurt some workloads, lets use the private inet socket generator. Not only this will remove one vulnerability, this will also improve performance of TCP flows using pmtudisc==IP_PMTUDISC_DONT Fixes: 73f156a6e8c1 ("inetpeer: get rid of ip_id_count") Signed-off-by: Eric Dumazet <edumazet@google.com> Reviewed-by: David Ahern <dsahern@kernel.org> Reported-by: Ray Che <xijiache@gmail.com> Cc: Willy Tarreau <w@1wt.eu> Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Diffstat (limited to 'Documentation/powerpc/booting.rst')
0 files changed, 0 insertions, 0 deletions