Re: [PATCH nf] netfilter: ebtables: also count base chain policies

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Mon, Jul 29, 2019 at 05:58:10PM +0200, Florian Westphal wrote:
> ebtables doesn't include the base chain policies in the rule count,
> so we need to add them manually when we call into the x_tables core
> to allocate space for the comapt offset table.
> 
> This lead syzbot to trigger:
> WARNING: CPU: 1 PID: 9012 at net/netfilter/x_tables.c:649
> xt_compat_add_offset.cold+0x11/0x36 net/netfilter/x_tables.c:649

Applied, thanks Florian.



[Index of Archives]     [Netfitler Users]     [Berkeley Packet Filter]     [LARTC]     [Bugtraq]     [Yosemite Forum]

  Powered by Linux