diff options
author | Jakub Kicinski <[email protected]> | 2022-07-26 19:53:09 -0700 |
---|---|---|
committer | Jakub Kicinski <[email protected]> | 2022-07-26 19:53:09 -0700 |
commit | e77ea97d2bd99b004e96c339ee22408c5475a52e (patch) | |
tree | cc6975faf310ce8bdd1f38b17c8fe57b1625ad52 /lib/mpi/mpi-mod.c | |
parent | e53f5293973181e8f557a7fef9a47f131fc3d4f0 (diff) | |
parent | 47f4f510ad586032b85c89a0773fbb011d412425 (diff) |
Merge git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf
Florian Westphal says:
====================
netfilter updates for net
Three late fixes for netfilter:
1) If nf_queue user requests packet truncation below size of l3 header,
we corrupt the skb, then crash. Reject such requests.
2) add cond_resched() calls when doing cycle detection in the
nf_tables graph. This avoids softlockup warning with certain
rulesets.
3) Reject rulesets that use nftables 'queue' expression in family/chain
combinations other than those that are supported. Currently the ruleset
will load, but when userspace attempts to reinject you get WARN splat +
packet drops.
* git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf:
netfilter: nft_queue: only allow supported familes and hooks
netfilter: nf_tables: add rescheduling points during loop detection walks
netfilter: nf_queue: do not allow packet truncation below transport header offset
====================
Link: https://lore.kernel.org/r/[email protected]
Signed-off-by: Jakub Kicinski <[email protected]>
Diffstat (limited to 'lib/mpi/mpi-mod.c')
0 files changed, 0 insertions, 0 deletions