From: Eric Dumazet <[email protected]> This is based on a report from David Dworken.
First patch implements RFC 6056 3.3.4 proposal. Second patch is adding a little bit of noise to make attacker life a bit harder. Eric Dumazet (2): tcp: change source port randomizarion at connect() time tcp: add some entropy in __inet_hash_connect() net/ipv4/inet_hashtables.c | 25 ++++++++++++++++++++++--- 1 file changed, 22 insertions(+), 3 deletions(-) -- 2.30.0.478.g8a0d178c01-goog
