On 7/11/19 9:28 AM, Christoph Paasch wrote:
> 

> Would it make sense to always allow the alloc in tcp_fragment when coming 
> from __tcp_retransmit_skb() through the retransmit-timer ?
> 
> AFAICS, the crasher was when an attacker sends "fake" SACK-blocks. Thus, we 
> would still be protected from too much fragmentation, but at least would 
> always allow the retransmission to go out.
> 
> 
I guess this could be done and hopefully something that can be backported 
without too much pain,
but I am sure some people will complain because reverting to timeouts might 
still
show regressions :/

Reply via email to