Commit b62cb6a
Paolo Abeni
Merge tag 'nf-24-06-27' of git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf
Pablo Neira Ayuso says:
====================
Netfilter fixes for net
The following patchset contains two Netfilter fixes for net:
Patch #1 fixes CONFIG_SYSCTL=n for a patch coming in the previous PR
to move the sysctl toggle to enable SRv6 netfilter hooks from
nf_conntrack to the core, from Jianguo Wu.
Patch #2 fixes a possible pointer leak to userspace due to insufficient
validation of NFT_DATA_VALUE.
Linus found this pointer leak to userspace via zdi-disclosures@ and
forwarded the notice to Netfilter maintainers, he appears as reporter
because whoever found this issue never approached Netfilter
maintainers neither via security@ nor in private.
netfilter pull request 24-06-27
* tag 'nf-24-06-27' of git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf:
netfilter: nf_tables: fully validate NFT_DATA_VALUE on store to data registers
netfilter: fix undefined reference to 'netfilter_lwtunnel_*' when CONFIG_SYSCTL=n
====================
Link: https://patch.msgid.link/20240626233845.151197-1-pablo@netfilter.org
Signed-off-by: Paolo Abeni <pabeni@redhat.com>4 files changed
Lines changed: 14 additions & 5 deletions
File tree
- include/net/netfilter
- net/netfilter
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
619 | 619 | | |
620 | 620 | | |
621 | 621 | | |
| 622 | + | |
| 623 | + | |
| 624 | + | |
| 625 | + | |
| 626 | + | |
622 | 627 | | |
623 | 628 | | |
624 | 629 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
117 | 117 | | |
118 | 118 | | |
119 | 119 | | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
120 | 123 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
5740 | 5740 | | |
5741 | 5741 | | |
5742 | 5742 | | |
5743 | | - | |
5744 | | - | |
| 5743 | + | |
5745 | 5744 | | |
5746 | 5745 | | |
5747 | 5746 | | |
| |||
11073 | 11072 | | |
11074 | 11073 | | |
11075 | 11074 | | |
| 11075 | + | |
| 11076 | + | |
| 11077 | + | |
11076 | 11078 | | |
11077 | 11079 | | |
11078 | 11080 | | |
| |||
11081 | 11083 | | |
11082 | 11084 | | |
11083 | 11085 | | |
11084 | | - | |
11085 | | - | |
11086 | 11086 | | |
11087 | 11087 | | |
11088 | 11088 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
132 | 132 | | |
133 | 133 | | |
134 | 134 | | |
135 | | - | |
| 135 | + | |
| 136 | + | |
136 | 137 | | |
137 | 138 | | |
138 | 139 | | |
| |||
0 commit comments