]> git.baikalelectronics.ru Git - kernel.git/commit
netfilter: ipset: enable memory accounting for ipset allocations
authorVasily Averin <vvs@virtuozzo.com>
Fri, 25 Sep 2020 08:56:02 +0000 (11:56 +0300)
committerPablo Neira Ayuso <pablo@netfilter.org>
Sun, 4 Oct 2020 19:08:25 +0000 (21:08 +0200)
commit7daf6a0207366f49230c14067818775558f9eb4c
treed713cfca44e780cd30cc0929ae16acc67acf572d
parent7b0b59d21f380bd1f459fc6b9c49a44a4b52915b
netfilter: ipset: enable memory accounting for ipset allocations

Currently netadmin inside non-trusted container can quickly allocate
whole node's memory via request of huge ipset hashtable.
Other ipset-related memory allocations should be restricted too.

v2: fixed typo ALLOC -> ACCOUNT

Signed-off-by: Vasily Averin <vvs@virtuozzo.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
net/netfilter/ipset/ip_set_core.c