aboutsummaryrefslogtreecommitdiffstats
path: root/net/Kconfig
diff options
context:
space:
mode:
authorPablo Neira Ayuso <pablo@netfilter.org>2014-10-07 19:02:11 +0200
committerPablo Neira Ayuso <pablo@netfilter.org>2014-10-07 20:16:31 +0200
commitf0d1f04f0a2f662b6b617e24d115fddcf6ef8723 (patch)
tree32d914b7f1baa5a5d5c01936616425226143c234 /net/Kconfig
parentnetfilter: kill nf_send_reset6() from include/net/netfilter/ipv6/nf_reject.h (diff)
downloadlinux-dev-f0d1f04f0a2f662b6b617e24d115fddcf6ef8723.tar.xz
linux-dev-f0d1f04f0a2f662b6b617e24d115fddcf6ef8723.zip
netfilter: fix wrong arithmetics regarding NFT_REJECT_ICMPX_MAX
NFT_REJECT_ICMPX_MAX should be __NFT_REJECT_ICMPX_MAX - 1. nft_reject_icmp_code() and nft_reject_icmpv6_code() are called from the packet path, so BUG_ON in case we try to access an unknown abstracted ICMP code. This should not happen since we already validate this from nft_reject_{inet,bridge}_init(). Fixes: 51b0a5d ("netfilter: nft_reject: introduce icmp code abstraction for inet and bridge") Reported-by: Dan Carpenter <dan.carpenter@oracle.com> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Diffstat (limited to 'net/Kconfig')
0 files changed, 0 insertions, 0 deletions