diff options
author | 2022-07-26 19:53:09 -0700 | |
---|---|---|
committer | 2022-07-26 19:53:09 -0700 | |
commit | e77ea97d2bd99b004e96c339ee22408c5475a52e (patch) | |
tree | cc6975faf310ce8bdd1f38b17c8fe57b1625ad52 /tools/perf/scripts/python/export-to-postgresql.py | |
parent | Merge tag 'for-net-2022-07-26' of git://git.kernel.org/pub/scm/linux/kernel/git/bluetooth/bluetooth (diff) | |
parent | netfilter: nft_queue: only allow supported familes and hooks (diff) | |
download | linux-dev-e77ea97d2bd99b004e96c339ee22408c5475a52e.tar.xz linux-dev-e77ea97d2bd99b004e96c339ee22408c5475a52e.zip |
Merge git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf
Florian Westphal says:
====================
netfilter updates for net
Three late fixes for netfilter:
1) If nf_queue user requests packet truncation below size of l3 header,
we corrupt the skb, then crash. Reject such requests.
2) add cond_resched() calls when doing cycle detection in the
nf_tables graph. This avoids softlockup warning with certain
rulesets.
3) Reject rulesets that use nftables 'queue' expression in family/chain
combinations other than those that are supported. Currently the ruleset
will load, but when userspace attempts to reinject you get WARN splat +
packet drops.
* git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf:
netfilter: nft_queue: only allow supported familes and hooks
netfilter: nf_tables: add rescheduling points during loop detection walks
netfilter: nf_queue: do not allow packet truncation below transport header offset
====================
Link: https://lore.kernel.org/r/20220726192056.13497-1-fw@strlen.de
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Diffstat (limited to 'tools/perf/scripts/python/export-to-postgresql.py')
0 files changed, 0 insertions, 0 deletions