public inbox for netdev@vger.kernel.org
 help / color / mirror / Atom feed
* [PATCH net 0/2] netfilter updates for net
@ 2026-02-25 13:06 Florian Westphal
  2026-02-25 13:06 ` [PATCH net 1/2] netfilter: nf_conntrack_h323: fix OOB read in decode_choice() Florian Westphal
  2026-02-25 13:06 ` [PATCH net 2/2] netfilter: nf_tables: unconditionally bump set->nelems before insertion Florian Westphal
  0 siblings, 2 replies; 12+ messages in thread
From: Florian Westphal @ 2026-02-25 13:06 UTC (permalink / raw)
  To: netdev
  Cc: Paolo Abeni, David S. Miller, Eric Dumazet, Jakub Kicinski,
	netfilter-devel, pablo

Hi,

This batch contains two bug fixes for the *net* tree:

1). The H323 conntrack helper has an OOB read bug, it should
    ensure at least 2 bytes are available before extracting the
    length.  From Vahagn Vardanian.

2). Inseo An reported a use-after-free in nf_tables.  Incorrect
    error unwind calls kfree() on a structure that was previously
    visible to another CPU. Fix from Pablo Neira Ayuso.

Please, pull these changes from:
The following changes since commit 2f61f38a217462411fed950e843b82bc119884cf:

  net: stmmac: fix timestamping configuration after suspend/resume (2026-02-24 17:46:15 -0800)

are available in the Git repository at:

  https://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf.git nf-26-02-25

for you to fetch changes up to e783189e0f6ccc834909323e0b67370ad93bb9c6:

  netfilter: nf_tables: unconditionally bump set->nelems before insertion (2026-02-25 11:52:33 +0100)

----------------------------------------------------------------
netfilter pull request nf-26-02-25

----------------------------------------------------------------
Pablo Neira Ayuso (1):
  netfilter: nf_tables: unconditionally bump set->nelems before insertion

Vahagn Vardanian (1):
  netfilter: nf_conntrack_h323: fix OOB read in decode_choice()

 net/netfilter/nf_conntrack_h323_asn1.c |  2 +-
 net/netfilter/nf_tables_api.c          | 30 ++++++++++++++------------
 2 files changed, 17 insertions(+), 15 deletions(-)
-- 
2.52.0

^ permalink raw reply	[flat|nested] 12+ messages in thread

end of thread, other threads:[~2026-02-26 17:19 UTC | newest]

Thread overview: 12+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-02-25 13:06 [PATCH net 0/2] netfilter updates for net Florian Westphal
2026-02-25 13:06 ` [PATCH net 1/2] netfilter: nf_conntrack_h323: fix OOB read in decode_choice() Florian Westphal
2026-02-26  9:10   ` Florian Westphal
2026-02-26 11:47     ` Paolo Abeni
2026-02-26 14:14       ` Florian Westphal
2026-02-26 11:48     ` Paolo Abeni
2026-02-26 14:00   ` patchwork-bot+netdevbpf
2026-02-25 13:06 ` [PATCH net 2/2] netfilter: nf_tables: unconditionally bump set->nelems before insertion Florian Westphal
2026-02-26  3:56   ` [net,2/2] " Jakub Kicinski
2026-02-26  8:19     ` Florian Westphal
2026-02-26 16:28       ` Pablo Neira Ayuso
2026-02-26 17:19         ` Paolo Abeni

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox