From f20f5f79909fdc6327fcd015a3850645a236729d Mon Sep 17 00:00:00 2001 From: Davide Caratti Date: Fri, 9 Sep 2016 16:02:22 +0200 Subject: macsec: fix input range of 'icvlen' parameter the maximum possible ICV length in a MACsec frame is 16 octects, not 32: fix get_icvlen() accordingly, so that a proper error message is displayed in case input 'icvlen' is greater than 16. Signed-off-by: Davide Caratti Acked-by: Phil Sutter Acked-by: Sabrina Dubroca --- ip/ipmacsec.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) (limited to 'ip/ipmacsec.c') diff --git a/ip/ipmacsec.c b/ip/ipmacsec.c index 2e670e9e..127fa1e3 100644 --- a/ip/ipmacsec.c +++ b/ip/ipmacsec.c @@ -152,9 +152,9 @@ static void get_icvlen(__u8 *icvlen, char *arg) if (ret) invarg("expected ICV length", arg); - if (*icvlen < MACSEC_MIN_ICV_LEN || *icvlen > MACSEC_MAX_ICV_LEN) + if (*icvlen < MACSEC_MIN_ICV_LEN || *icvlen > MACSEC_STD_ICV_LEN) invarg("ICV length must be in the range {" - STR(MACSEC_MIN_ICV_LEN) ".." STR(MACSEC_MAX_ICV_LEN) + STR(MACSEC_MIN_ICV_LEN) ".." STR(MACSEC_STD_ICV_LEN) "}", arg); } -- cgit v1.2.3