diff options
| author | David S. Miller <[email protected]> | 2017-08-24 18:49:19 +0000 |
|---|---|---|
| committer | David S. Miller <[email protected]> | 2017-08-24 18:49:19 +0000 |
| commit | af57d2b720252baca5421ec58628da626e1862dc (patch) | |
| tree | 14bfa04f9de7521cef419b2b7ed1c5a42c35d220 /net/tipc/socket.c | |
| parent | Merge branch 'bnxt_en-bug-fixes' (diff) | |
| parent | netfilter: nf_tables: Fix nft limit burst handling (diff) | |
| download | kernel-af57d2b720252baca5421ec58628da626e1862dc.tar.gz kernel-af57d2b720252baca5421ec58628da626e1862dc.zip | |
Merge git://git.kernel.org/pub/scm/linux/kernel/git/pablo/nf
Pablo Neira Ayuso says:
====================
Netfilter fixes for net
The following patchset contains Netfilter fixes for your net tree,
they are:
1) Fix use after free of struct proc_dir_entry in ipt_CLUSTERIP, patch
from Sabrina Dubroca.
2) Fix spurious EINVAL errors from iptables over nft compatibility layer.
3) Reload pointer to ip header only if there is non-terminal verdict,
ie. XT_CONTINUE, otherwise invalid memory access may happen, patch
from Taehee Yoo.
4) Fix interaction between SYNPROXY and NAT, SYNPROXY adds sequence
adjustment already, however from nf_nat_setup() assumes there's not.
Patch from Xin Long.
5) Fix burst arithmetics in nft_limit as Joe Stringer mentioned during
NFWS in Faro. Patch from Andy Zhou.
====================
Signed-off-by: David S. Miller <[email protected]>
Diffstat (limited to 'net/tipc/socket.c')
0 files changed, 0 insertions, 0 deletions
