• David S. Miller's avatar
    Merge git://git.kernel.org/pub/scm/linux/kernel/git/pablo/nf · 0c84ea17
    David S. Miller authored
    Pablo Neira Ayuso says:
    
    ====================
    Netfilter fixes for net
    
    The following patchset contains Netfilter fixes for you net tree,
    they are:
    
    1) There was a race condition between parallel save/swap and delete,
       which resulted a kernel crash due to the increase ref for save, swap,
       wrong ref decrease operations. Reported and fixed by Vishwanath Pai.
    
    2) OVS should call into CT NAT for packets of new expected connections only
       when the conntrack state is persisted with the 'commit' option to the
       OVS CT action. From Jarno Rajahalme.
    
    3) Resolve kconfig dependencies with new OVS NAT support. From Arnd Bergmann.
    
    4) Early validation of entry->target_offset to make sure it doesn't take us
       out from the blob, from Florian Westphal.
    
    5) Again early validation of entry->next_offset to make sure it doesn't take
       out from the blob, also from Florian.
    
    6) Check that entry->target_offset is always of of sizeof(struct xt_entry)
       for unconditional entries, when checking both from check_underflow()
       and when checking for loops in mark_source_chains(), again from
       Florian.
    
    7) Fix inconsistent behaviour in nfnetlink_queue when
       NFQA_CFG_F_FAIL_OPEN is set and netlink_unicast() fails due to buffer
       overrun, we have to reinject the packet as the user expects.
    
    8) Enforce nul-terminated table names from getsockopt GET_ENTRIES
       requests.
    
    9) Don't assume skb->sk is set from nft_bridge_reject and synproxy,
       this fixes a recent update of the code to namespaceify
       ip_default_ttl, patch from Liping Zhang.
    
    This batch comes with four patches to validate x_tables blobs coming
    from userspace. CONFIG_USERNS exposes the x_tables interface to
    unpriviledged users and to be honest this interface never received the
    attention for this move away from the CAP_NET_ADMIN domain. Florian is
    working on another round with more patches with more sanity checks, so
    expect a bit more Netfilter fixes in this development cycle than usual.
    ====================
    Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
    0c84ea17
conntrack.c 35.7 KB