summaryrefslogtreecommitdiff
path: root/net/netfilter/nf_flow_table_offload.c
diff options
context:
space:
mode:
authorCong Wang <xiyou.wangcong@gmail.com>2020-02-02 20:30:53 -0800
committerPablo Neira Ayuso <pablo@netfilter.org>2020-02-07 15:53:31 +0100
commit8d0015a7ab76b8b1e89a3e5f5710a6e5103f2dd5 (patch)
tree3aecb3dc3a0d48cca539380ab4b80cfb7bdcb481 /net/netfilter/nf_flow_table_offload.c
parentc4a3922d2d20c710f827d3a115ee338e8d0467df (diff)
netfilter: xt_hashlimit: limit the max size of hashtable
The user-specified hashtable size is unbound, this could easily lead to an OOM or a hung task as we hold the global mutex while allocating and initializing the new hashtable. Add a max value to cap both cfg->size and cfg->max, as suggested by Florian. Reported-and-tested-by: syzbot+adf6c6c2be1c3a718121@syzkaller.appspotmail.com Signed-off-by: Cong Wang <xiyou.wangcong@gmail.com> Reviewed-by: Florian Westphal <fw@strlen.de> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Diffstat (limited to 'net/netfilter/nf_flow_table_offload.c')
0 files changed, 0 insertions, 0 deletions