stream-tcp-reassemble: fix reassembly direction for FIN packets

Suricata invokes the stream reassembly logic only for the current packet
direction if the packet contains a FIN flag. However, this does not
handle the case in which the packet ACKs data from the opposing direction.
This patch forces the invocation of the stream reassembly logic
on both direction when Suricata sees a FIN packet.
pull/6879/head
Angelo Mirabella 5 years ago committed by Victor Julien
parent 9e096dda4e
commit 41a139b590

@ -1853,7 +1853,11 @@ int StreamTcpReassembleHandleSegment(ThreadVars *tv, TcpReassemblyThreadCtx *ra_
} else if (p->tcph->th_flags & TH_RST) { // accepted rst
dir = UPDATE_DIR_PACKET;
} else if ((p->tcph->th_flags & TH_FIN) && ssn->state > TCP_TIME_WAIT) {
dir = UPDATE_DIR_PACKET;
if (p->tcph->th_flags & TH_ACK) {
dir = UPDATE_DIR_BOTH;
} else {
dir = UPDATE_DIR_PACKET;
}
} else if (ssn->state == TCP_CLOSED) {
dir = UPDATE_DIR_BOTH;
}

Loading…
Cancel
Save