commit | 7d7d7e02111e9a4dc9d0658597f528f815d820fd | [log] [tgz] |
---|---|---|
author | Florian Westphal <fw@strlen.de> | Tue Feb 27 19:42:35 2018 +0100 |
committer | Pablo Neira Ayuso <pablo@netfilter.org> | Mon Mar 05 23:15:43 2018 +0100 |
tree | 79624163e94c944c0b0ad6efea062b96ef8d3560 | |
parent | 9782a11efc072faaf91d4aa60e9d23553f918029 [diff] |
netfilter: compat: reject huge allocation requests no need to bother even trying to allocating huge compat offset arrays, such ruleset is rejected later on anyway becaus we refuse to allocate overly large rule blobs. However, compat translation happens before blob allocation, so we should add a check there too. This is supposed to help with fuzzing by avoiding oom-killer. Signed-off-by: Florian Westphal <fw@strlen.de> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>