]> git.baikalelectronics.ru Git - kernel.git/commit
netfilter: nf_tables: check for overflow of rule dlen field
authorPatrick McHardy <kaber@trash.net>
Tue, 3 Mar 2015 20:04:19 +0000 (20:04 +0000)
committerPablo Neira Ayuso <pablo@netfilter.org>
Wed, 4 Mar 2015 17:46:05 +0000 (18:46 +0100)
commit35bdbd3798f05acba21d937323192fc16e8be108
tree9124100fd1cb08ea518f56d01b7f0907fd362fe7
parent83dffe424db124bee1d2c1adfdebdcc05c6d06db
netfilter: nf_tables: check for overflow of rule dlen field

Check that the space required for the expressions doesn't exceed the
size of the dlen field, which would lead to the iterators crashing.

Signed-off-by: Patrick McHardy <kaber@trash.net>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
net/netfilter/nf_tables_api.c