From: Jan Engelhardt Date: Wed, 27 Feb 2008 20:20:41 +0000 (-0800) Subject: [NETFILTER]: xt_conntrack: fix IPv4 address comparison X-Git-Tag: firefly_0821_release~21773^2~216 X-Git-Url: http://demsky.eecs.uci.edu/git/?a=commitdiff_plain;h=6556874dc3770aefae89907b3cf9be8e23d66137;p=firefly-linux-kernel-4.4.55.git [NETFILTER]: xt_conntrack: fix IPv4 address comparison Signed-off-by: Jan Engelhardt Signed-off-by: Patrick McHardy Signed-off-by: David S. Miller --- diff --git a/net/netfilter/xt_conntrack.c b/net/netfilter/xt_conntrack.c index dd192ac74b4a..0c50b2894055 100644 --- a/net/netfilter/xt_conntrack.c +++ b/net/netfilter/xt_conntrack.c @@ -122,7 +122,7 @@ conntrack_addrcmp(const union nf_inet_addr *kaddr, const union nf_inet_addr *umask, unsigned int l3proto) { if (l3proto == AF_INET) - return (kaddr->ip & umask->ip) == uaddr->ip; + return ((kaddr->ip ^ uaddr->ip) & umask->ip) == 0; else if (l3proto == AF_INET6) return ipv6_masked_addr_cmp(&kaddr->in6, &umask->in6, &uaddr->in6) == 0;