]> git.baikalelectronics.ru Git - kernel.git/commit
netfilter: nf_tables: check for overflow of rule dlen field
authorPatrick McHardy <kaber@trash.net>
Tue, 3 Mar 2015 20:04:19 +0000 (20:04 +0000)
committerPablo Neira Ayuso <pablo@netfilter.org>
Wed, 4 Mar 2015 17:46:05 +0000 (18:46 +0100)
commitb2b5320a16f549b7e6f16b60f4ab14c0a4c57683
tree9124100fd1cb08ea518f56d01b7f0907fd362fe7
parent37a10c7ac5d6a5e5f24f959327281b36bb23bd0d
netfilter: nf_tables: check for overflow of rule dlen field

Check that the space required for the expressions doesn't exceed the
size of the dlen field, which would lead to the iterators crashing.

Signed-off-by: Patrick McHardy <kaber@trash.net>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
net/netfilter/nf_tables_api.c