diff options
author | 2019-04-01 13:08:54 +0200 | |
---|---|---|
committer | 2019-04-15 07:31:44 +0200 | |
commit | 3c79107631db1f7fd32cf3f7368e4672004a3010 (patch) | |
tree | e8eb82a458ef088d823e96d66d6ee2ff40e70774 /tools/perf/scripts/python/export-to-sqlite.py | |
parent | ipvs: do not schedule icmp errors from tunnels (diff) | |
download | wireguard-linux-3c79107631db1f7fd32cf3f7368e4672004a3010.tar.xz wireguard-linux-3c79107631db1f7fd32cf3f7368e4672004a3010.zip |
netfilter: ctnetlink: don't use conntrack/expect object addresses as id
else, we leak the addresses to userspace via ctnetlink events
and dumps.
Compute an ID on demand based on the immutable parts of nf_conn struct.
Another advantage compared to using an address is that there is no
immediate re-use of the same ID in case the conntrack entry is freed and
reallocated again immediately.
Fixes: 3583240249ef ("[NETFILTER]: nf_conntrack_expect: kill unique ID")
Fixes: 7f85f914721f ("[NETFILTER]: nf_conntrack: kill unique ID")
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Diffstat (limited to 'tools/perf/scripts/python/export-to-sqlite.py')
0 files changed, 0 insertions, 0 deletions