netfilter-devel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [PATCH 0/3] Netfilter/IPVS fixes for net
@ 2019-02-13 17:47 Pablo Neira Ayuso
  2019-02-13 17:47 ` [PATCH 1/3] netfilter: compat: initialize all fields in xt_init Pablo Neira Ayuso
                   ` (3 more replies)
  0 siblings, 4 replies; 7+ messages in thread
From: Pablo Neira Ayuso @ 2019-02-13 17:47 UTC (permalink / raw)
  To: netfilter-devel; +Cc: davem, netdev

Hi David,

The following patchset contains Netfilter/IPVS fixes for net:

1) Missing structure initialization in ebtables causes splat with
   32-bit user level on a 64-bit kernel, from Francesco Ruggeri.

2) Missing dependency on nf_defrag in IPVS IPv6 codebase, from
   Andrea Claudi.

3) Fix possible use-after-free from release path of target extensions.

You can pull these changes from:

  git://git.kernel.org/pub/scm/linux/kernel/git/pablo/nf.git

Thanks!

----------------------------------------------------------------

The following changes since commit cf657d22ee1f0e887326a92169f2e28dc932fd10:

  net/x25: do not hold the cpu too long in x25_new_lci() (2019-02-11 13:20:14 -0800)

are available in the git repository at:

  git://git.kernel.org/pub/scm/linux/kernel/git/pablo/nf.git HEAD

for you to fetch changes up to 753c111f655e38bbd52fc01321266633f022ebe2:

  netfilter: nft_compat: use-after-free when deleting targets (2019-02-13 18:14:54 +0100)

----------------------------------------------------------------
Andrea Claudi (1):
      ipvs: fix dependency on nf_defrag_ipv6

Francesco Ruggeri (1):
      netfilter: compat: initialize all fields in xt_init

Pablo Neira Ayuso (1):
      netfilter: nft_compat: use-after-free when deleting targets

 net/netfilter/ipvs/Kconfig      |  1 +
 net/netfilter/ipvs/ip_vs_core.c | 10 ++++------
 net/netfilter/ipvs/ip_vs_ctl.c  | 10 ++++++++++
 net/netfilter/nft_compat.c      |  3 ++-
 net/netfilter/x_tables.c        |  2 +-
 5 files changed, 18 insertions(+), 8 deletions(-)

^ permalink raw reply	[flat|nested] 7+ messages in thread
* [PATCH 0/3] Netfilter/IPVS fixes for net
@ 2014-08-01 16:40 Pablo Neira Ayuso
  2014-08-02 23:49 ` David Miller
  0 siblings, 1 reply; 7+ messages in thread
From: Pablo Neira Ayuso @ 2014-08-01 16:40 UTC (permalink / raw)
  To: netfilter-devel; +Cc: davem, netdev

Hi David,

The following patchset contains Netfilter/IPVS fixes for your net tree,
they are:

1) Maintain all DSCP and ECN bits for IPv6 tun forwarding. This
   resolves an inconsistency between IPv4 and IPv6 behaviour.
   Patch from Alex Gartrell via Simon Horman.

2) Fix unnoticeable blink in xt_LED when the led-always-blink option is
   used, from Jiri Prchal.

3) Add missing return in nft_del_setelem(), otherwise this results in a
   double call of nft_data_uninit() in the nf_tables code, from Thomas Graf.

You can pull these changes from:

  git://git.kernel.org/pub/scm/linux/kernel/git/pablo/nf.git

Thanks!

----------------------------------------------------------------

The following changes since commit 2627b7e15c5064ddd5e578e4efd948d48d531a3f:

  ipvs: avoid netns exit crash on ip_vs_conn_drop_conntrack (2014-07-16 09:39:28 +0900)

are available in the git repository at:

  git://git.kernel.org/pub/scm/linux/kernel/git/pablo/nf.git master

for you to fetch changes up to 0dc1362562a2e8b82a6be8d3ae307a234f28f9bc:

  netfilter: nf_tables: Avoid duplicate call to nft_data_uninit() for same key (2014-08-01 18:14:49 +0200)

----------------------------------------------------------------
Alex Gartrell (1):
      ipvs: Maintain all DSCP and ECN bits for ipv6 tun forwarding

Jiri Prchal (1):
      netfilter: xt_LED: fix too short led-always-blink

Thomas Graf (1):
      netfilter: nf_tables: Avoid duplicate call to nft_data_uninit() for same key

 net/netfilter/ipvs/ip_vs_xmit.c |    2 +-
 net/netfilter/nf_tables_api.c   |    1 +
 net/netfilter/xt_LED.c          |   10 +++++++---
 3 files changed, 9 insertions(+), 4 deletions(-)

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2019-02-14  0:15 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2019-02-13 17:47 [PATCH 0/3] Netfilter/IPVS fixes for net Pablo Neira Ayuso
2019-02-13 17:47 ` [PATCH 1/3] netfilter: compat: initialize all fields in xt_init Pablo Neira Ayuso
2019-02-13 17:47 ` [PATCH 2/3] ipvs: fix dependency on nf_defrag_ipv6 Pablo Neira Ayuso
2019-02-13 17:47 ` [PATCH 3/3] netfilter: nft_compat: use-after-free when deleting targets Pablo Neira Ayuso
2019-02-14  0:15 ` [PATCH 0/3] Netfilter/IPVS fixes for net David Miller
  -- strict thread matches above, loose matches on Subject: below --
2014-08-01 16:40 Pablo Neira Ayuso
2014-08-02 23:49 ` David Miller

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).