On Do, 2015-01-15 at 22:34 +0100, Hagen Paul Pfeifer wrote: > Reduce the attack vector and stop generating IPv6 Fragment Header for > paths with an MTU smaller than the minimum required IPv6 MTU > size (1280 byte) - called atomic fragments. > > See IETF I-D "Deprecating the Generation of IPv6 Atomic Fragments" [1] > for more information and how this "feature" can be misused. > > [1] https://tools.ietf.org/html/draft-ietf-6man-deprecate-atomfrag-generation-00 > > Cc: stable@xxxxxxxxxxxxxxx > Signed-off-by: Fernando Gont <fgont@xxxxxxxxxxxxxxx> > Signed-off-by: Hagen Paul Pfeifer <hagen@xxxxxxxx> Acked-by: Hannes Frederic Sowa <hannes@xxxxxxxxxxxxxxxxxxx> I think this is the correct way forward on how to deal with atomic fragments. Hagen, do you submit patches to remove dst_allfrag/RTAX_FEATURE_ALLFRAG, IPCORK_ALLFRAG, etc. for net-next, too? Thanks, Hannes -- To unsubscribe from this list: send the line "unsubscribe stable" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html