]> git.ipfire.org Git - thirdparty/kernel/stable.git/commit
xfrm: set ipv4 no_pmtu_disc flag only on output sa when direction is set
authorAntony Antony <antony.antony@secunet.com>
Thu, 11 Dec 2025 10:30:27 +0000 (11:30 +0100)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Fri, 23 Jan 2026 10:18:35 +0000 (11:18 +0100)
commita2a3c7bf2c0cdcf2f9fabb9f6c6f9416b1307d9a
tree36e967dd7a649f0d20cf4c500ea38a7d4f6c36b4
parentf93a187c255f53279badcdca3f84e777926cee03
xfrm: set ipv4 no_pmtu_disc flag only on output sa when direction is set

[ Upstream commit c196def07bbc6e8306d7a274433913444b0db20a ]

The XFRM_STATE_NOPMTUDISC flag is only meaningful for output SAs, but
it was being applied regardless of the SA direction when the sysctl
ip_no_pmtu_disc is enabled. This can unintentionally affect input SAs.

Limit setting XFRM_STATE_NOPMTUDISC to output SAs when the SA direction
is configured.

Closes: https://github.com/strongswan/strongswan/issues/2946
Fixes: a4a87fa4e96c ("xfrm: Add Direction to the SA in or out")
Signed-off-by: Antony Antony <antony.antony@secunet.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
net/xfrm/xfrm_state.c